Skip to main content
Plynt
Security

Security decisions you can see in the product.

Plynt's security posture is expressed in how the product is shaped: scoped access, isolation, and audit at every layer.

Access controls

Access to a workspace is granted per member. Roles determine which modules and actions are reachable. Session state is bound to the identity, not shared across workspaces.

  • Per-workspace membership
  • Role-based module and action scoping
  • Least-privilege defaults

Encryption in transit

Traffic between your browser and Plynt is served over HTTPS. Additional protections applied by our infrastructure providers cover storage-level protections; contact us for details relevant to your review.

  • HTTPS on every page
  • Infrastructure-provided storage protections

Isolation model

Workspaces are the fundamental unit of isolation. Queries and records remain scoped to the active workspace. Identity can move between workspaces; data does not.

  • Scope-enforced at query time
  • No cross-workspace exposure

Audit logging

Every state change writes to an append-only log with actor, action and timestamp. Admins can review the log for their workspace.

  • Append-only per workspace
  • Reviewable by workspace admins

Incident response

If we identify an incident affecting your workspace, we contact affected admins by email, describe the impact, and follow up in writing once resolution and root-cause review are complete.

  • Email notification to affected admins
  • Written follow-up after resolution

Report a security concern

For responsible disclosures and security questions, email us. We reply to every message.

Email security