Security
Security & Trust
Plenum combines database-enforced tenant isolation, encrypted infrastructure, and application access controls to protect your business data.
Encryption
Tenant data is encrypted in transit and at rest.
Tenant Isolation
PostgreSQL row-level security isolates each tenant.
Managed Infrastructure
Infrastructure providers operate the underlying hosting services.
Row-Level Security (RLS)
Every tenant's data is isolated with PostgreSQL row-level security enforced at the database layer; application code cannot query across tenants.
- Tenant context is applied to database access.
- Isolation policies are enforced by PostgreSQL.
- Application queries remain scoped to the active tenant.
Defense at the data layer
Tenant isolation does not depend on a page or screen hiding another company's data. Database policies constrain which tenant rows an authenticated request can access.
Encryption standards
At rest: Stored tenant data and managed backups are encrypted at rest.
In transit: Connections use TLS 1.2+ with modern cipher suites.
Key management: Infrastructure providers manage encryption for their hosted services.
Encryption
Tenant data is encrypted in transit and at rest using controls provided by Plenum and its infrastructure providers.
Infrastructure & Compliance
Infrastructure
- Hosted services use managed cloud infrastructure.
- We target 99.9% monthly availability, subject to the exclusions in our Terms.
- Backups are managed as part of the hosted database service.
Compliance context
Our infrastructure providers maintain independent compliance programs. Contact security@plenum.pro for current documentation about Plenum's security practices.
Access Controls
Authentication and application permissions limit access according to a user's account and assigned responsibilities.
- Authenticated sessions are required for customer workspaces.
- Application roles limit available actions and records.
- Tenant context is carried into database access.
- Security-relevant application activity may be recorded for investigation.
Incident Response
We investigate reported security issues, contain confirmed incidents, and provide notices when required by applicable law or contract.
Reporting security issues
Send vulnerability reports and security questions to our security contact.
security@plenum.proOur Security Practices
Database-Level Isolation
Every tenant's data is isolated with PostgreSQL row-level security enforced at the database layer; application code cannot query across tenants.
Encryption Standards
Tenant data is encrypted in transit using TLS 1.2+ with modern cipher suites and encrypted at rest through managed infrastructure controls.
Access Controls
Authenticated sessions, application roles, and tenant context work together to limit access to customer workspaces and records.
Audit Logging
Plenum records security-relevant application activity where needed to operate and investigate the service. Retention depends on the record type and applicable requirements.
Infrastructure Security
Production services run on managed cloud infrastructure. Our infrastructure providers maintain independent security and compliance programs.
Vulnerability Management
We review dependency and platform security updates and prioritize remediation according to risk. Reports can be sent to security@plenum.pro.
Data Backup & Recovery
Managed backups support service recovery. Backups age out on a rolling schedule and are not presented as a customer archive.
Employee Access
Production access is limited to authorized personnel for operational and support needs and is subject to access controls.
Security, clearly scoped
Security is shared across Plenum, our infrastructure providers, and your account administrators. We publish the controls we can describe accurately and update this page as those controls change.
Ask a security question