Security
Last updated: 06/12/2026
This page describes the security controls PlotCipher has in place to protect customer accounts, content, and the Service. We update it when controls change; the date above reflects the most recent revision.
Encryption in transit
All traffic to the Platform is served over HTTPS with TLS 1.2 or higher. Internal service-to-service traffic in our AWS VPC uses TLS where supported by the underlying protocol.
Encryption at rest
The primary user and content database (Amazon RDS Postgres) is encrypted at rest using AWS-managed KMS keys. Object storage (Amazon S3) uses default server-side encryption.
Credential handling
User passwords are hashed using bcrypt (work factor 12+) and never stored in plaintext. API and infrastructure secrets are stored in AWS Secrets Manager with least-privilege IAM access. We never log raw passwords, payment card data, or secrets.
Identity & access
PlotCipher staff use single-sign-on with required multi-factor authentication. Production access is granted on a need-to-know basis and time-bound. We recommend customers enable in-product MFA when available.
Infrastructure
Hosted on Amazon Web Services in the United States (US-East-1 / US-West-2). Backend runs on managed container services with isolated VPC subnets. Application updates ship via reviewed CI/CD pipelines.
Payment security
Payments are processed by Stripe, a Level 1 PCI-DSS Service Provider. PlotCipher never sees or stores full payment card numbers, CVV, or bank routing details — Stripe handles all card data inside their PCI environment.
Logging & monitoring
Application and infrastructure logs are retained for 90 days. We monitor for anomalous traffic patterns, failed-login bursts, and dependency vulnerabilities. Critical errors page the on-call engineer.
Vulnerability management
Dependencies are scanned continuously and patched on a risk-based schedule. We accept good-faith security research at mark@tryplotcipher.com and follow a coordinated 90-day disclosure timeline.
Incident response
We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. In the event of a confirmed personal data breach, we notify affected customers and applicable regulators within the timeframes required by law — in most US states, without unreasonable delay and (for sensitive data) typically within 30 days of confirmation.
Disaster recovery
The primary database is backed up automatically with point-in-time recovery enabled. Backups are retained for up to 35 days. Recovery time objective (RTO) is 24 hours and recovery point objective (RPO) is 1 hour for the production database.
Sub-processors
Our complete subprocessor list with data-types processed and regions is published at /subprocessors. We provide 30 days' advance notice of material changes.
Compliance posture
PlotCipher is not currently SOC 2 certified. We follow SOC 2 Type II control families (access, change management, monitoring, incident response, vendor management) as our internal standard and plan to pursue formal certification as the customer base grows. Enterprise customers may request our internal control summary under NDA via mark@tryplotcipher.com.
Reporting a vulnerability
Report security issues to mark@tryplotcipher.com. We commit to acknowledging your report within 2 business days. Please do not publicly disclose before we have had a reasonable opportunity to remediate (we target 90 days for complete fix and disclosure).