Everything your security review will ask, answered in one page.
We build software for hospitals, fund administrators, regulators and the people who file with them. The bar is real.
On this page
- Posture, controls, and the receipts
- Who else touches your data
- Need the full DPA, security package, or a signed audit letter?
- Six disciplines.One studio. Designed to ship
- Software we built, in production right now
- Trusted by the names you already trust
- Awake somewhere on earth.Watching your systems
- A studio without borders
SOC 2 Type II
Audit in progress with a Big Four firm. Report expected Q4 2026. Letter of engagement available under NDA.
ISO 27001
ISMS implementation complete. Stage 1 audit scheduled Q3 2026.
GDPR & UK GDPR
DPA available off the shelf. SCCs Module 2 and Module 3. UK IDTA addendum on request.
HIPAA-ready
BAA available for healthcare engagements. PHI handling controls documented.
PCI DSS
We do not store cardholder data ourselves. Integrations go through Stripe, Adyen or your acquirer of choice.
KVKK (Turkey)
VERBIS registered. Data localization options for Istanbul-resident workloads.
Posture, controls, and the receipts.
Access
SSO with MFA enforced across all production systems. Hardware keys for admin roles. Role-based access reviewed quarterly. Joiner-mover-leaver runbook with same-day deprovisioning. No shared accounts, ever.
Code and change management
Required peer review on every change. Branch protections, signed commits, dependency scanning (Snyk + GitHub Advanced Security), secret scanning, container image signing. No direct pushes to main. Production deploys gated by automated tests and manual approval for high-risk paths.
Infrastructure
AWS primary, GCP and Hetzner for specific workloads. Terraform for everything. Private subnets by default, public only where intentional. VPC flow logs, GuardDuty, CloudTrail to immutable S3 with object lock. Daily encrypted backups with quarterly restore drills.
Encryption
TLS 1.3 in transit, AES-256 at rest. Customer-managed KMS keys available on Enterprise. Field-level encryption for PII and PHI workloads.
Penetration testing
External pen-test annually by an independent CREST-accredited firm. Quarterly internal red-team exercise by our own Stinger Security team. Continuous bug bounty via HackerOne for production properties.
Vulnerability management
Critical CVEs patched within 24 hours of disclosure. High within 7 days. Medium within 30. SLA tracked publicly on status.plutobee.com.
Incident response
24/7 on-call rotation with documented runbooks. First customer notification within 24 hours of confirmed material incident. Post-incident report within 5 business days. We do not blame, we fix and document.
Business continuity
Multi-region active-passive failover. RTO 4 hours, RPO 15 minutes for tier-1 systems. Tested quarterly. Annual full DR drill.
Who else touches your data.
Current as of May 2026. Updates published at /dpa. 30-day notice on material additions.
Report a vulnerability
Coordinated disclosure, 90-day standard window. Hall of fame for verified reports.
Or email security@plutobee.com (PGP key on request).
Vendor security review
SIG Lite, CAIQ Lite, and HECVAT Lite responses prepared. We can usually return a full questionnaire in 5 business days.
Need the full DPA, security package, or a signed audit letter?
Talk to our trust team →Want to walk through this live?
Book a 25-minute call with a senior engineer. No prep needed. We will share notes and a written summary after.