1. Encryption
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Sensitive fields are additionally encrypted at the application layer with per-tenant keys.
2. Access controls
Role-based access controls, granular permissions, SSO/SAML (Enterprise), and mandatory 2FA for all staff. Customer data is accessed only when explicitly authorized for support.
3. Infrastructure
Hosted on ISO 27001 / SOC 2 certified cloud infrastructure with multi-region redundancy, automated patching, and isolated tenant environments.
4. Compliance
ThePlexa is built to support HIPAA, GDPR, and PCI-DSS obligations for our customers. Business Associate Agreements and Data Processing Addenda are available on request.
5. Backups & disaster recovery
Continuous backups with point-in-time recovery. RPO < 1 hour, RTO < 4 hours. Disaster recovery is exercised quarterly.
6. Responsible disclosure
We welcome security research. Report findings to support@theplexa.com using our published PGP key. We respond within 72 hours and credit responsible reporters.
Questions about this policy?
Email us at legal@theplexa.com or reach out via our contact page.
Contact us