Security

Security & Trust

Plenum combines database-enforced tenant isolation, encrypted infrastructure, and application access controls to protect your business data.

Encryption

Tenant data is encrypted in transit and at rest.

Tenant Isolation

PostgreSQL row-level security isolates each tenant.

Managed Infrastructure

Infrastructure providers operate the underlying hosting services.

Row-Level Security (RLS)

Every tenant's data is isolated with PostgreSQL row-level security enforced at the database layer; application code cannot query across tenants.

  • Tenant context is applied to database access.
  • Isolation policies are enforced by PostgreSQL.
  • Application queries remain scoped to the active tenant.

Defense at the data layer

Tenant isolation does not depend on a page or screen hiding another company's data. Database policies constrain which tenant rows an authenticated request can access.

Encryption standards

At rest: Stored tenant data and managed backups are encrypted at rest.

In transit: Connections use TLS 1.2+ with modern cipher suites.

Key management: Infrastructure providers manage encryption for their hosted services.

Encryption

Tenant data is encrypted in transit and at rest using controls provided by Plenum and its infrastructure providers.

Infrastructure & Compliance

Infrastructure

  • Hosted services use managed cloud infrastructure.
  • We target 99.9% monthly availability, subject to the exclusions in our Terms.
  • Backups are managed as part of the hosted database service.

Compliance context

Our infrastructure providers maintain independent compliance programs. Contact security@plenum.pro for current documentation about Plenum's security practices.

Access Controls

Authentication and application permissions limit access according to a user's account and assigned responsibilities.

  • Authenticated sessions are required for customer workspaces.
  • Application roles limit available actions and records.
  • Tenant context is carried into database access.
  • Security-relevant application activity may be recorded for investigation.

Incident Response

We investigate reported security issues, contain confirmed incidents, and provide notices when required by applicable law or contract.

Reporting security issues

Send vulnerability reports and security questions to our security contact.

security@plenum.pro

Our Security Practices

Database-Level Isolation

Every tenant's data is isolated with PostgreSQL row-level security enforced at the database layer; application code cannot query across tenants.

Encryption Standards

Tenant data is encrypted in transit using TLS 1.2+ with modern cipher suites and encrypted at rest through managed infrastructure controls.

Access Controls

Authenticated sessions, application roles, and tenant context work together to limit access to customer workspaces and records.

Audit Logging

Plenum records security-relevant application activity where needed to operate and investigate the service. Retention depends on the record type and applicable requirements.

Infrastructure Security

Production services run on managed cloud infrastructure. Our infrastructure providers maintain independent security and compliance programs.

Vulnerability Management

We review dependency and platform security updates and prioritize remediation according to risk. Reports can be sent to security@plenum.pro.

Data Backup & Recovery

Managed backups support service recovery. Backups age out on a rolling schedule and are not presented as a customer archive.

Employee Access

Production access is limited to authorized personnel for operational and support needs and is subject to access controls.

Security, clearly scoped

Security is shared across Plenum, our infrastructure providers, and your account administrators. We publish the controls we can describe accurately and update this page as those controls change.

Ask a security question