エンタープライズレベルの保護システム
Our security program combines layered access controls, encryption, continuous monitoring, and regular security testing to protect your account and data.
Last updated: July 29, 2026
ゼロトレランスのセキュリティへの取り組み
We maintain a strict security program with layered controls, automated testing in our build pipeline, and continuous monitoring.
Strong security posture
OWASP トップ 10 と高度な脅威保護
Controls designed to defend against the most common modern web threats
アクセス制御の不備
Role-based access control with RS256-signed JWTs, session binding, and privilege-escalation checks
暗号化の失敗
AES-256-GCM encryption for sensitive data, with secrets and database credentials managed in a hardened vault issuing short-lived credentials
インジェクション攻撃
パラメータ化クエリ、ASTベースのインジェクション検知、Row Level Security
セキュリティ設定ミス
Automated security testing in our build pipeline and hardened service configuration
脆弱なコンポーネント
自動SBOM生成、依存関係スキャン、DevSecOpsパイプライン
サーバーサイドリクエストフォージェリ
SSRF protections with network segmentation between services
Encryption
Strong, standards-based encryption in transit and at rest
Data at Rest — AES-256-GCM
Data in Transit — TLS 1.3
Security Capabilities
The systems and practices protecting the marketplace
Automated Security Testing
Static analysis, dependency and secret scanning run automatically in our build pipeline
Layered Security Controls
Access control, encryption, network segmentation, and monitoring across the platform
Incident Response
Automated alerting on security events, with session revocation and access controls applied during response
Fail-Closed Compliance Checks
Sanctions and watchlist screening blocks money movement when a check cannot be completed
Continuous Monitoring
Automated metrics, logging, and alerting across the platform
Tamper-Evident Audit Trail
Money-movement events are cryptographically signed into an append-only, tamper-evident audit trail.
セキュリティコンプライアンスのフレームワーク
企業のセキュリティ標準への包括的な準拠
決済セキュリティ
Payment Card Industry Data Security Standard - 完全なコンプライアンスフレームワーク
GDPR第32条
EU一般データ保護規則 - 高度なセキュリティ措置
CCPAデータ主体権利
California Consumer Privacy Act - 自動化されたコンプライアンスシステム
DevSecOpsパイプライン
自動脆弱性管理を伴う継続的なセキュリティ統合
Threat Detection & Response
Monitoring, alerting, and containment for security incidents
Automated Detection
自動化されたインシデント対応
Our Security Practices
The controls and safeguards protecting the marketplace
セキュリティの質問と回答
セキュリティ実装に関する技術的な詳細
How do you test your own security?
Static code analysis, dependency scanning, and secret detection run automatically in our build pipeline, and we perform regular internal security reviews. Independent external penetration testing is part of our certification roadmap.
What happens when a security incident is detected?
Security events raise alerts to our monitoring stack. Depending on the event, we revoke sessions, force re-authentication, and apply access restrictions while we investigate.
How do you protect money movement?
Card payments and seller payouts run on Stripe Connect. Funds are held by Stripe, not in a PlugZ bank account; on separate-charge orders the payment settles in PlugZ's Stripe balance before it is transferred to the seller. Sanctions and watchlist screening runs fail-closed, meaning money does not move if a compliance check cannot be completed, and money-movement events are cryptographically signed into an append-only audit trail.
How are my credentials and sessions protected?
Passwords are hashed and compared in constant time, sessions are bound to their context, and access tokens are RS256-signed and published through a JWKS endpoint. The current signing key has not been rotated yet.
What encryption do you use?
TLS 1.3 in transit, and AES-256-GCM for sensitive data at rest, with secrets and database credentials issued as short-lived dynamic credentials from a hardened vault.
軍事レベルのセキュリティを体験
Join a marketplace built with layered security controls and continuous monitoring.
"Security controls built into the platform, not bolted on."