trust & security

your work is yours. quietly.

plumo holds your team's work — issues, time entries, comments, plans — and we take that responsibility seriously. here's how we keep it safe and how to reach us if something's off.

how plumo handles your data

the short version, honestly.

we list everything below with a status. live means it's running today. soon means actively in progress with a target. planned means committed but not started. we don't list things we haven't decided on.

encryption

live

data encrypted at rest with AES-256. transport with TLS 1.3. per-tenant database isolation. backups are encrypted with their own rotating keys.

hosting region

live

aws eu-central-1 (frankfurt) by default — keeps your data inside the EU. enterprise tier can request paris (eu-west-3) or tunis-region mirrors for GDPR + MENA proximity.

backups

live

automated daily snapshots, 30-day retention. weekly long-term backups held for 12 months. tested restore drills run monthly — we know they work.

GDPR compliance

live

plumo is GDPR-compliant by design. data minimization, lawful basis documented, DPA available on request for paid tiers. you can export or delete everything with one click.

SOC 2 (type II)

in progress

SOC 2 Type II audit under way with our auditor. target completion: q3 2026. we can share the Type I report and a controls overview today on request, under NDA.

SSO & SAML

live

SAML 2.0 SSO with Okta, Google Workspace, Azure AD. SCIM provisioning on the enterprise tier. 2FA available on every plan. magic-link sign-in by default — passwords are optional.

data export & portability

live

your data is yours. one-click export to JSON or CSV — projects, issues, comments, time entries, the whole thing. if you ever leave, plumo doesn't hold it hostage.

audit logs

live

every meaningful action — including AI / MCP activity — is logged with actor, timestamp, and source. admins can stream logs to s3 or siem on the enterprise tier.

penetration testing

live

annual third-party pentest by a CREST-accredited firm. summary report available on request, under NDA, for paid customers.

AI & MCP policy

live

your data is never used to train third-party models. MCP sessions are permission-scoped, fully logged, and require explicit consent for write actions. read more in the AI handling addendum.

ISO 27001

planned · 2027

ISO 27001 certification is on the roadmap once SOC 2 Type II lands. internal ISMS already aligned with the standard.

incident response

live

24/7 on-call rotation. customer notification within 72 hours of a confirmed material incident (or sooner, when GDPR requires). post-mortems published in field notes.

sub-processors

the small list of people who help us run plumo.

we keep this list short. when it changes, paid customers are notified at least 30 days before any new sub-processor goes live.

providerpurposeregion
amazon web servicesprimary hosting & databaseeu-central-1 (frankfurt)
cloudflareCDN, DDoS protectionglobal edge, eu-default
postmarktransactional emailus, EU-routed
stripebilling (paid tiers only)ireland
plausibleprivacy-friendly analytics (no cookies)germany

found something? tell us, gently.

email security@plumo.app with a description and steps to reproduce. we'll respond within one business day. we run a quiet bug-bounty for material findings — ask for details when you reach out.

email security@plumo.app
hello.