ACCESS / SCOPE
SECURITY / DOCUMENTED PRODUCT CONTROLS
Security information with implementation boundaries.
Plynt documents how identity, workspace membership, role-aware actions, HTTPS and change history are intended to reduce risk. No software can promise absolute security.
Report a security concern↗01
Identity and access
Access starts with an individual account and workspace membership. Administrators are responsible for reviewing members, roles and former collaborators.
- 01Individual identities↗
- 02Workspace membership↗
- 03Least access needed for the role↗
02
Transport and infrastructure
Public Plynt surfaces are served over HTTPS. Storage-level and infrastructure protections depend on the hosting environment and are reviewed during plan-specific security discussions.
- 01HTTPS for browser traffic↗
- 02Restricted operational access↗
- 03Backups and recovery handled operationally↗
03
Workspace isolation model
Workspaces are intended to define the tenant boundary. Queries and actions should evaluate the active workspace and membership before accessing a record.
- 01Active-workspace context↗
- 02Membership validation↗
- 03No intentional cross-workspace sharing↗
04
Audit and monitoring
Material state changes are designed to retain actor, action and time context. Audit coverage, customer visibility and retention vary by feature and plan.
- 01Change context↗
- 02Admin review where available↗
- 03No claim of universal immutable logging↗
05
Responsible disclosure
Email info@plynt.us with SECURITY in the subject. Describe impact and reproduction safely; do not access, retain or disclose other users' data.
- 01Good-faith reports welcomed↗
- 02No destructive testing↗
- 03Written acknowledgement and follow-up↗
ONE WORKSPACE / CONNECTED OPERATIONS
Replace reconciliation with connected work.