Security
Security, scale and resilience
Security built for the trust sector: independently penetration-tested, encrypted in transit and at rest, with audit logs and point-in-time recovery.
At a glance
- Data hosting
- Google Firestore, in the EU (europe-west3)
- Encryption
- In transit (TLS, HTTPS only) and at rest
- Access
- Row-level permissions; mandatory 2FA for code access
- Audit logs
- On all data changes; administrators can revert unintentional modifications
- Penetration testing
- Annual, independent; attestations on request
- Backups
- Daily, kept 30 days, plus 7-day point-in-time recovery
- Regulation
- GDPR applies; registered with the ICO
- AI training
- Your data is never used to train any AI models
01
Infrastructure
Plinth is hosted on a multi-cloud serverless architecture, designed for scalability and resilience.
- Database: Google Firestore, hosted within the EU (europe-west3). A serverless NoSQL database designed for automatic scalability.
- Web hosting: Static assets cached and served via Vercel, remaining accessible even if serverless functions fail.
- Analytics: Cloud Elasticsearch (managed by elastic.co on Google Cloud) for fast, complex queries and reporting.
02
Encryption and data protection
- All data encrypted in transit and at rest in our Firestore database.
- All traffic encrypted via TLS. All sites served exclusively over HTTPS.
- Credentials managed by Firebase Authentication. We never store or see a plaintext password.
- API secrets and third-party keys stored as encrypted environment variables, never checked into code.
03
Access control
- Firestore integrated with Firebase Authentication providing row-level permissions on all data.
- All API calls to personal data are authenticated. Each organization manages their own access.
- Code access restricted to approved team members with mandatory 2FA on GitHub.
- Full audit logs for all data changes, allowing administrators to revert unintentional modifications.
04
Testing and code quality
- Annual independent penetration testing by qualified third parties. Attestations available on request.
- Static analysis, automated QA and security testing, and peer code review before every deployment.
- New versions deployed to a staging environment first. Any deployment can be rolled back with one click.
05
Backups and resilience
- Daily emergency backups stored in a Google Cloud storage bucket (EU, europe-west3) for 30 days.
- Point-in-time recovery for the last 7 days: version control and querying of historical data.
- Backup restoration regularly tested in staging. Point-in-time recovery bounds data loss to minutes within the 7-day window; restores are measured in hours, not days.
06
Compliance
- GDPR by default. Hosting in the EU puts your data under GDPR, a stricter regime than US law requires, carrying enforceable rights to deletion, portability and 72-hour breach notification, whichever country you operate in. Your data is never used to train any AI models.
- Registered with the ICO. Named board representative for security of the service.
- Public, product, and professional indemnity insurance maintained.
- Internal incident management via dedicated Slack channel with immediate full-team awareness.
Questions about security?
For further details, see our Privacy Policy and Terms of Service.