Built to be enterprise-defensible
The documents your security, privacy, and legal teams need to onboard PlotCipher — in one place. Updated as the platform changes; material changes are disclosed with notice.
Compliance posture
Security
Required for diligenceEncryption, identity, infrastructure, incident response, vulnerability management, and disaster recovery.
Read →
Privacy Policy
How we collect, use, retain, and share personal information. State-by-state rights matrix for CCPA, TDPSA, VCDPA, CPA, CTDPA, UCPA, OCPA, DPDPA.
Read →
Subprocessors
Complete vendor inventory with purpose, data types, region. Material changes announced with 30 days notice.
Read →
AI Use Policy
NewHow AI is used inside the Service, what data is sent to model providers, prohibited customer uses, training-data position.
Read →
Enterprise contracting
Master Services Agreement (MSA)
Standard enterprise services agreement. Available as the base for negotiated MSAs.
Read →
Data Processing Addendum (DPA)
Controller-processor framework with subprocessor list and SCC where applicable.
Read →
Service Level Agreement (SLA)
Uptime, response time, and service-credit commitments for paid tiers.
Read →
Open Source Licenses
Third-party open-source software shipped with PlotCipher and the license terms attached.
Read →
Certifications & roadmap
We're building toward SOC 2 Type II
PlotCipher follows SOC 2 Type II control families (access management, change control, monitoring, incident response, vendor management) as our internal standard. Formal attestation will be pursued as the customer base grows. In the interim, enterprise customers may request our internal control summary under NDA.
SOC 2 Type II
In progress — controls implemented
CCPA / CPRA
Compliant — DSAR portal live
PCI-DSS
Out of scope (Stripe processes cards)
GDPR
Not currently targeting EU users
Have a security or procurement question we haven't answered?
Email mark@tryplotcipher.com