ThePlexa.
Trust

Security at ThePlexa

Healthcare data demands a higher bar. ThePlexa is engineered with defense-in-depth controls, audited regularly, and aligned with leading security frameworks.

Last updated: June 1, 2026

1. Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Sensitive fields are additionally encrypted at the application layer with per-tenant keys.

2. Access controls

Role-based access controls, granular permissions, SSO/SAML (Enterprise), and mandatory 2FA for all staff. Customer data is accessed only when explicitly authorized for support.

3. Infrastructure

Hosted on ISO 27001 / SOC 2 certified cloud infrastructure with multi-region redundancy, automated patching, and isolated tenant environments.

4. Compliance

ThePlexa is built to support HIPAA, GDPR, and PCI-DSS obligations for our customers. Business Associate Agreements and Data Processing Addenda are available on request.

5. Backups & disaster recovery

Continuous backups with point-in-time recovery. RPO < 1 hour, RTO < 4 hours. Disaster recovery is exercised quarterly.

6. Responsible disclosure

We welcome security research. Report findings to support@theplexa.com using our published PGP key. We respond within 72 hours and credit responsible reporters.

Questions about this policy?

Email us at legal@theplexa.com or reach out via our contact page.

Contact us