PlugZ LogoPlugZ
Security built into the platform

Sistema de protección para entornos empresariales

Our security program combines layered access controls, encryption, continuous monitoring, and regular security testing to protect your account and data.

Last updated: July 29, 2026

Compromiso estricto de seguridad

We maintain a strict security program with layered controls, automated testing in our build pipeline, and continuous monitoring.

Strong security posture

OWASP Top 10 y protección avanzada contra amenazas

Controls designed to defend against the most common modern web threats

Control de acceso deficiente

Role-based access control with RS256-signed JWTs, session binding, and privilege-escalation checks

Fallos criptográficos

AES-256-GCM encryption for sensitive data, with secrets and database credentials managed in a hardened vault issuing short-lived credentials

Ataques de inyección

Consultas parametrizadas, detección de inyección basada en AST y seguridad a nivel de fila (Row Level Security)

Configuración de seguridad incorrecta

Automated security testing in our build pipeline and hardened service configuration

Componentes vulnerables

Generación automatizada de SBOM, escaneo de dependencias y canalización DevSecOps

Falsificación de solicitudes del lado del servidor

SSRF protections with network segmentation between services

Encryption

Strong, standards-based encryption in transit and at rest

Data at Rest — AES-256-GCM

AES-256-GCM encryption for sensitive personal, identity, and payment data
Column-level encryption for the most sensitive fields
Secrets and database credentials managed in a hardened vault with short-lived dynamic credentials
Políticas de seguridad a nivel de fila (RLS) en PostgreSQL
Financial log encryption with a separate key hierarchy

Data in Transit — TLS 1.3

TLS 1.3 con Perfect Forward Secrecy
RS256-signed JWTs with a publicly published JWKS endpoint, HS256 downgrade rejected at the gateway — the current signing key has not been rotated yet
Comparación de contraseñas resistente a ataques de temporización
Session binding and hijacking prevention
Encrypted WebSocket connections

Security Capabilities

The systems and practices protecting the marketplace

Automated Security Testing

Static analysis, dependency and secret scanning run automatically in our build pipeline

Layered Security Controls

Access control, encryption, network segmentation, and monitoring across the platform

Incident Response

Automated alerting on security events, with session revocation and access controls applied during response

Fail-Closed Compliance Checks

Sanctions and watchlist screening blocks money movement when a check cannot be completed

Continuous Monitoring

Automated metrics, logging, and alerting across the platform

Tamper-Evident Audit Trail

Money-movement events are cryptographically signed into an append-only, tamper-evident audit trail.

Marco de cumplimiento de seguridad

Cumplimiento integral con estándares de seguridad empresariales

Seguridad de pagos

Estándar de Seguridad de Datos de la Industria de Tarjetas de Pago (PCI-DSS): marco de cumplimiento completo

Artículo 32 del GDPR

Reglamento General de Protección de Datos de la UE (GDPR): medidas de seguridad avanzadas

Derechos del titular de los datos según la CCPA

Ley de Privacidad del Consumidor de California (CCPA): sistema de cumplimiento automatizado

Canalización DevSecOps

Integración continua de seguridad con gestión automatizada de vulnerabilidades

Threat Detection & Response

Monitoring, alerting, and containment for security incidents

Automated Detection

Detección de anomalías en los patrones de comportamiento de los usuarios
Risk scoring and alerting on suspicious activity
Rate limiting and abuse controls
Machine-learning-assisted fraud prevention

Respuesta automatizada a incidentes

Alerting and containment for security incidents
Alertas de incidentes de seguridad en tiempo real
Session revocation and forced re-authentication where needed
Análisis y mejora posteriores al incidente

Our Security Practices

The controls and safeguards protecting the marketplace

Multicapa
Security Controls
Automated
Security Testing in CI
24/7
Monitoreo en tiempo real
Fail-Closed
Compliance Checks

Preguntas y respuestas de seguridad

Detalles técnicos sobre nuestra implementación de seguridad

How do you test your own security?

Static code analysis, dependency scanning, and secret detection run automatically in our build pipeline, and we perform regular internal security reviews. Independent external penetration testing is part of our certification roadmap.

What happens when a security incident is detected?

Security events raise alerts to our monitoring stack. Depending on the event, we revoke sessions, force re-authentication, and apply access restrictions while we investigate.

How do you protect money movement?

Card payments and seller payouts run on Stripe Connect. Funds are held by Stripe, not in a PlugZ bank account; on separate-charge orders the payment settles in PlugZ's Stripe balance before it is transferred to the seller. Sanctions and watchlist screening runs fail-closed, meaning money does not move if a compliance check cannot be completed, and money-movement events are cryptographically signed into an append-only audit trail.

How are my credentials and sessions protected?

Passwords are hashed and compared in constant time, sessions are bound to their context, and access tokens are RS256-signed and published through a JWKS endpoint. The current signing key has not been rotated yet.

What encryption do you use?

TLS 1.3 in transit, and AES-256-GCM for sensitive data at rest, with secrets and database credentials issued as short-lived dynamic credentials from a hardened vault.

Experimente la seguridad de nivel empresarial

Join a marketplace built with layered security controls and continuous monitoring.

"Security controls built into the platform, not bolted on."

Layered Security • Continuous Monitoring