Home/Security & your data
Security & your data
Your data, wherever you choose to keep it.
A consultant works inside a client's finance system. Asking them to upload that client's plan, budget, risk register and defect list to someone else's server is a harder sell than most tools admit. So cloud storage is a choice you make per project, not a condition of using the product — and a local project never leaves your machine at all.
Where data lives today
Two layers, both local.
Browser storage
Automatic. Your work is held by the browser on the machine you are using, so closing a tab does not lose an afternoon. This layer needs nothing configured and is how the hosted build works.
A file you chose
Optional and recommended on the desktop build. Link the project to a .json file anywhere on your disk and it autosaves about a second after you stop typing. You picked the location, so you decide whether that is a local folder, a network share or a synced drive.
What leaves
What crosses the network, and when.
| Data | Where it goes |
|---|---|
| Project Content Tasks, hours, rates, budgets, risks, defects, migration counts, notes, client names | Stays on your machine. In browser storage and, if you link one, in the file you chose. It is not transmitted to us. |
| Exports | Go wherever you send them. A JSON or CSV export is an ordinary file on your disk from the moment it is created. |
| Subscription and Licensing | Checking that a subscription is active is a network call. It carries licence status, not project content. |
| Fonts and Page Assets | The application requests web fonts from a public font CDN when it opens. No project data is attached to that request. If your client's policy forbids outbound CDN calls, tell us and we will send a build with the fonts embedded. This website serves its own fonts and makes no third-party requests at all. |
If your client's security review needs this in writing against their specific questions, ask us and we will answer them directly rather than pointing at a trust page.
The commitment
You can always get your data out.
In the current version we hold nothing, so there is no version of a billing dispute, an acquisition, an outage or a shutdown in which your live delivery plans become inaccessible to you.
A subscription lapsing costs you the application. It does not cost you the project file, which is sitting where you put it, in a documented JSON format, readable without us.
A cloud project is different by design: its data sits on a server so several people can work on the same plan. Two things hold there too. It is a choice you make per project, not a condition of using the product. And one click exports the whole thing as JSON you can read without us, whatever your subscription is doing.
Your backup responsibility
The other side of local data is that backing it up is yours. Browser storage can be cleared by the browser, by a policy, or by somebody tidying up.
- Link the project to a real file, do not rely on browser storage alone
- Put that file somewhere that is already backed up
- Export a JSON copy at each gate — it is one click and it is a clean restore point
Questions from a client security review?
Send them over. We will answer the actual questions rather than send a certificate.