Security

Last updated: 06/12/2026

This page describes the security controls PlotCipher has in place to protect customer accounts, content, and the Service. We update it when controls change; the date above reflects the most recent revision.

  • Encryption in transit

    All traffic to the Platform is served over HTTPS with TLS 1.2 or higher. Internal service-to-service traffic in our AWS VPC uses TLS where supported by the underlying protocol.

  • Encryption at rest

    The primary user and content database (Amazon RDS Postgres) is encrypted at rest using AWS-managed KMS keys. Object storage (Amazon S3) uses default server-side encryption.

  • Credential handling

    User passwords are hashed using bcrypt (work factor 12+) and never stored in plaintext. API and infrastructure secrets are stored in AWS Secrets Manager with least-privilege IAM access. We never log raw passwords, payment card data, or secrets.

  • Identity & access

    PlotCipher staff use single-sign-on with required multi-factor authentication. Production access is granted on a need-to-know basis and time-bound. We recommend customers enable in-product MFA when available.

  • Infrastructure

    Hosted on Amazon Web Services in the United States (US-East-1 / US-West-2). Backend runs on managed container services with isolated VPC subnets. Application updates ship via reviewed CI/CD pipelines.

  • Payment security

    Payments are processed by Stripe, a Level 1 PCI-DSS Service Provider. PlotCipher never sees or stores full payment card numbers, CVV, or bank routing details — Stripe handles all card data inside their PCI environment.

  • Logging & monitoring

    Application and infrastructure logs are retained for 90 days. We monitor for anomalous traffic patterns, failed-login bursts, and dependency vulnerabilities. Critical errors page the on-call engineer.

  • Vulnerability management

    Dependencies are scanned continuously and patched on a risk-based schedule. We accept good-faith security research at mark@tryplotcipher.com and follow a coordinated 90-day disclosure timeline.

Incident response

We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed personal data breach, we notify affected customers and applicable regulators within the timeframes required by law — in most US states, without unreasonable delay and (for sensitive data) typically within 30 days of confirmation.

Disaster recovery

The primary database is backed up automatically with point-in-time recovery enabled. Backups are retained for up to 35 days. Recovery time objective (RTO) is 24 hours and recovery point objective (RPO) is 1 hour for the production database.

Sub-processors

Our complete subprocessor list with data-types processed and regions is published at /subprocessors. We provide 30 days' advance notice of material changes.

Compliance posture

PlotCipher is not currently SOC 2 certified. We follow SOC 2 Type II control families (access, change management, monitoring, incident response, vendor management) as our internal standard and plan to pursue formal certification as the customer base grows. Enterprise customers may request our internal control summary under NDA via mark@tryplotcipher.com.

Reporting a vulnerability

Report security issues to mark@tryplotcipher.com. We commit to acknowledging your report within 2 business days. Please do not publicly disclose before we have had a reasonable opportunity to remediate (we target 90 days for complete fix and disclosure).

Free forever · No credit card

Start finding deals today.