Security

Know what leaves Pokor,what stays, and what you control.

Planning data should not disappear into a black box. Here is how Pokor handles access, connected backlogs, optional AI requests, payments, and retention.

Security controls

Start with the questions your team is likely to ask

Each answer names the control and points to the policy or evidence behind it. For procurement documents and service status, use the trust center.

Will Pokor store another password?

Passwordless account access

Sign in with a one-time email code or an approved OAuth provider. One-time codes expire, while OAuth tokens and connected AI keys are encrypted at rest.

Can Pokor charge or see a card directly?

Payments stay with Stripe

Stripe handles subscription and AI-credit payments. Pokor stores the billing identifiers and lifecycle records it needs, not card numbers, CVCs, or bank details.

Does every integration receive broad access?

Provider scopes and explicit actions

Connected tools use provider-approved OAuth scopes. Content enters a room when someone imports it, and estimate write-back runs only when an organizer configures it.

Is data encrypted?

Protected in transit and at rest

Connections use TLS. Sensitive integration tokens and connected AI-provider keys are encrypted at rest.

Data flow

Connected work moves only when someone asks it to

Pokor connects the planning room to the tools your team already uses. Import and write-back actions remain deliberate rather than becoming an invisible background sync.

Jira, Notion, and GitHub

Bring selected backlog items into a session. When the organizer enables and configures it, finalized estimates can be written back to supported source fields.

CSV files

The browser parses the file first. Only the rows selected for import are sent to Pokor.

Slack and Discord

The bots respond where a team invokes the Pokor command; they do not silently read every conversation in a workspace or server.

AI boundaries

AI acts on a request. It does not watch the room.

An eligible signed-in participant or organizer must explicitly trigger an AI action. Story explanation and session summary are available to eligible signed-in participants; estimate suggestions and disagreement analysis remain organizer-controlled.

Only the content required for that action is sent to the model provider. Voter identities are anonymized before vote data leaves the browser. Hosted AI traffic goes through Cloudflare AI Gateway and is not used to train third-party models.

Your provider, your terms

Organizer customers can connect an OpenAI, Anthropic, Google, or Grok API key. That key is encrypted at rest and requests then go directly to the selected provider under its terms.

Review AI data handling in the privacy policy

Short-lived room state

Ephemeral state such as pending join requests expires automatically after 10 minutes.

Guests stay guests

Guest participation uses a random token, not an email account. Signing out removes the guest cookie and data associated with that token.

EU-hosted infrastructure

Pokor application infrastructure is hosted in Europe, and connections are encrypted in transit with TLS.

Review evidence

Policies and live evidence, in one place

We prefer specific, reviewable claims. The trust center brings the supporting documents and live service evidence together.

  • Privacy policy

    Collected data, third-party services, retention, and user rights.

    Read the privacy policy
  • Terms of service

    Account, subscription, content, and service conditions.

    Read the terms
  • Data Processing Addendum

    GDPR processor obligations, subprocessors, transfers, and notification terms.

    Download the DPA
  • Live service status

    Current uptime and active or resolved incidents.

    Open the status page

Found a security issue?

Send the details to [email protected]. We review every report.

Report an issue

Cookie preferences

Essential cookies keep Pokor working. Optional analytics only load if you say yes. Privacy policy