pliuzv0.1.x

Security & compliance

Don’t trust our audit claims. Verify them yourself.

Concrete claims, not slogans. Every item below is mechanically enforced or you can verify it yourself. Spotted a gap? Email founder@pliuz.com — we will fix it.

  • EU-hosted by default

    Supabase Frankfurt (eu-central-1). US region planned, not default.

  • Append-only events table

    Cryptographic source of truth. Convenience tables are projections.

  • SHA-256 hash chain

    Verifiable by you via SELECT * FROM pliuz_verify_chain()

  • RLS on every table (19/19)

    Row-level security on all 19 public base tables; deny-by-default for anon/authenticated, backend service_role paths stay tenant-scoped.

  • No LLMs in the critical path

    Policy evaluation is deterministic JSONLogic. Your payload never touches an external model.

  • SDK-side redaction

    @gated(redact=[...]) and gated({ redact: [...] }) send masked fields to Pliuz. We never see the original.

  • Per-event auto_approve_source

    Every audit row says exactly what allowed the action — policy, tool_flag, standing_grant, or a named human.

  • Right-to-erasure without breaking the chain

    Tier-based retention nulls raw PII and on-demand tenant erasure wipes personal data — the hash chain stays verifiable because it stores hashes of the arguments, not the raw arguments.

  • Management API on least-privilege machine tokens

    Scoped plm_live_ tokens provision agents, policies, and tools — they never run approvals nor mint agent keys, and every write is attributed via acted_via in the audit trail.

  • Strict CSP, nonce per request

    Content-Security-Policy with a per-request nonce on every response — no inline-script execution from injected markup.

  • Liveness endpoint at /api/v1/health

    Unauthenticated health check for your uptime monitoring — no tenant data, no side effects.

  • Sub-processors listed publicly

    Supabase (EU), Vercel (EU), Plausible (EU), Resend (EU), Cloudflare, Slack — at /legal/subprocessors

  • DPA at /legal/dpa

    Template available on request; signature pending counsel review and entity formation.

  • Encryption at rest AES-256-GCM

    Bound per tenant (AAD = tenant_id), so an encrypted blob cannot be reused across tenants. TLS 1.3 in transit, no exceptions.

  • No training on customer payloads

    No payload inspection for "product improvement". No retention beyond your configured policy.

For your CISO

DPA: signable at /legal/dpa. Available before contract — we do not gate this behind a sales call.

Sub-processors: public list at /legal/subprocessors. Currently Supabase (EU), Vercel (EU), Plausible (EU), Resend (EU), Cloudflare, and Slack. Any addition triggers a 30-day notice to existing customers.

Pen-test access: design-partner tier gets a copy of our most recent internal pen-test report. Email founder@pliuz.com.

SOC2 Type I: in progress (target Q4 2026). Type II to follow.

EU AI Act: built to satisfy Article 12 (audit logs) and Article 14 (human oversight). Legal certification is your auditor call, not ours.

Talk to us directly.

Compliance questions get a real answer in <24h. No sales gating.

Email founder@pliuz.com