Trust
Security & Trust at Plumb
Plumb is a compliance scanner — buyers will rightly ask us to meet the same standards we audit them against. This page is our honest answer: what we protect, how we protect it, who else touches your data, and where we are on formal attestation.
Last updated May 14, 2026 UTC. If you need this page as a PDF for procurement, email security@plumbcompliance.com.
Security controls
The web-verifiable subset of our security posture. The full set (access reviews, change management, incident response) lives in our SOC 2 readiness documentation.
TLS in transit
In placeAll traffic between your browser and Plumb is encrypted with TLS 1.2 or 1.3. HSTS is set site-wide with a one-year max-age and includeSubDomains.
Encryption at rest
In placeAll scan reports, screenshots, and database rows are stored on Azure-managed encrypted storage (AES-256). Credentials submitted for authenticated scans are encrypted with AES-256-GCM using per-scan keys.
Authentication
In placeEmail magic-link sign-in via Auth.js. No passwords stored, no password reset flow to phish. MFA via passkey is on the short-term roadmap.
Stored credential isolation
In placeCredentials provided for authenticated-route scans are kept only for the lifetime of the scan and discarded immediately after the report is generated. They are not logged, not retained, and not accessible to anyone after the scan completes.
Network security headers
In placeContent-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy are set on every Plumb response. Verify with curl -I or your favorite header inspector.
Vulnerability disclosure
In placeSecurity researchers can report issues to security@plumbcompliance.com. We respond within two business days and acknowledge good-faith reports in a public hall of fame.
Penetration testing
PlannedExternal pen-test scheduled within the SOC 2 Type II observation window. Findings will be remediated and re-tested before report finalization.
SOC 2 Type II attestation
In progressCurrently in the SOC 2 readiness phase. Observation window for the Type II report opens in Q4 2026; final attestation expected by mid-2027. Type I attestation may be issued in advance for buyers who need a bridging document.
What data we hold
The smallest amount that lets the product work. Specifically:
- Account email. Used for sign-in and to deliver reports. Not shared, never sold, never used for marketing without opt-in.
- Scan inputs. The URL you submit and any options (WCAG level, max pages). Stored against your account so the dashboard shows scan history.
- Generated reports and screenshots. The PDF and full-page screenshots from each scan. Kept for as long as your account is active so you can re-download.
- Subscription state. Whether you have an active Standard or Pro subscription. We do not store card details — Stripe handles those.
- Operational logs. Standard application metrics — timestamps, scan duration, success/failure status, rate-limit counters. Used for reliability and billing reconciliation only.
Data retention
- Reports and screenshots are retained while your account is active. Closing your account removes them within 30 days. You can request earlier deletion at any time.
- Scan credentials (for authenticated scans) are deleted as soon as the scan completes. They are not retained, not logged, and not recoverable.
- Operational logs are retained for 90 days, then aggregated and the per-request records purged.
- Billing records are retained for the duration required by U.S. tax and accounting regulations — typically seven years.
Subprocessors
External services Plumb routes some of your data through. We pick vendors with their own SOC 2 attestations and prefer US-region processing throughout.
| Vendor | Purpose | Data received | Location |
|---|---|---|---|
| Microsoft Azure | Application hosting and blob storage for scan reports | Scan inputs, generated reports, page screenshots | United States (East US region) |
| Resend | Transactional email (magic-link sign-in, scan-complete notifications) | Account email address, scan-completion metadata | United States |
| Stripe | Subscription billing and payment processing | Email, billing details, subscription tier | United States |
| Anthropic | AI-augmented compliance review (paid tiers only) | Page DOM snapshots and screenshots for AI analysis | United States |
We'll give thirty days' notice on this page before adding or changing a subprocessor that touches customer data.
Where data lives
All Plumb production infrastructure runs in U.S. Azure regions. We do not replicate customer data outside the United States. This is deliberate: Plumb scopes its compliance modules to U.S. obligations (ADA, CCPA, HIPAA, PCI-DSS, FERPA, SOC 2), so a U.S.-only data footprint matches our regulatory surface.
If you have data-residency requirements for non-U.S. jurisdictions, get in touch — we'll be honest about whether Plumb is the right fit for your deployment.
Reporting a security issue
If you believe you have found a security issue in Plumb, please email security@plumbcompliance.com with reproduction steps. We commit to:
- Acknowledging your report within two business days.
- Providing a status update within seven business days.
- Not pursuing legal action against good-faith security research that doesn't harm our users or our service.
- Crediting researchers (with their permission) in a public hall of fame on this page once a fix has shipped.
For non-security questions about how we handle your data, contact privacy@plumbcompliance.com.
Enterprise procurement
If you need a SIG, CAIQ, custom security questionnaire, mutual NDA, DPA, or BAA, email security@plumbcompliance.com. We'll respond within two business days with the requested documentation or an honest answer about where we are on producing it.