Act
plutbee

Everything your security review will ask, answered in one page.

We build software for hospitals, fund administrators, regulators and the people who file with them. The bar is real.

Scroll
Trust center

Everything your security review will ask, answered in one page.

We build software for hospitals, fund administrators, regulators and the people who file with them. The bar is real.

SOC 2 Type II

Audit in progress with a Big Four firm. Report expected Q4 2026. Letter of engagement available under NDA.

ISO 27001

ISMS implementation complete. Stage 1 audit scheduled Q3 2026.

GDPR & UK GDPR

DPA available off the shelf. SCCs Module 2 and Module 3. UK IDTA addendum on request.

HIPAA-ready

BAA available for healthcare engagements. PHI handling controls documented.

PCI DSS

We do not store cardholder data ourselves. Integrations go through Stripe, Adyen or your acquirer of choice.

KVKK (Turkey)

VERBIS registered. Data localization options for Istanbul-resident workloads.

How we operate

Posture, controls, and the receipts.

Access

SSO with MFA enforced across all production systems. Hardware keys for admin roles. Role-based access reviewed quarterly. Joiner-mover-leaver runbook with same-day deprovisioning. No shared accounts, ever.

Code and change management

Required peer review on every change. Branch protections, signed commits, dependency scanning (Snyk + GitHub Advanced Security), secret scanning, container image signing. No direct pushes to main. Production deploys gated by automated tests and manual approval for high-risk paths.

Infrastructure

AWS primary, GCP and Hetzner for specific workloads. Terraform for everything. Private subnets by default, public only where intentional. VPC flow logs, GuardDuty, CloudTrail to immutable S3 with object lock. Daily encrypted backups with quarterly restore drills.

Encryption

TLS 1.3 in transit, AES-256 at rest. Customer-managed KMS keys available on Enterprise. Field-level encryption for PII and PHI workloads.

Penetration testing

External pen-test annually by an independent CREST-accredited firm. Quarterly internal red-team exercise by our own Stinger Security team. Continuous bug bounty via HackerOne for production properties.

Vulnerability management

Critical CVEs patched within 24 hours of disclosure. High within 7 days. Medium within 30. SLA tracked publicly on status.plutobee.com.

Incident response

24/7 on-call rotation with documented runbooks. First customer notification within 24 hours of confirmed material incident. Post-incident report within 5 business days. We do not blame, we fix and document.

Business continuity

Multi-region active-passive failover. RTO 4 hours, RPO 15 minutes for tier-1 systems. Tested quarterly. Annual full DR drill.

Sub-processors

Who else touches your data.

Current as of May 2026. Updates published at /dpa. 30-day notice on material additions.

Vendor
Purpose
Region
Optional?
AWS
Primary cloud, compute, storage
US, EU, Asia-Pacific
No
Cloudflare
CDN, WAF, DDoS
Global
No
Anthropic
LLM inference (Claude)
US
Yes - opt out
Stripe
Payments
US, EU, UK
Yes - if you use billing
Sentry
Error monitoring
EU, US
Yes - opt out
Datadog
Observability, logs, APM
EU, US
Yes - opt out
1Password
Internal secrets vault (not customer data)
Canada, EU
No
Google Workspace
Internal email and docs
US, EU
No

Report a vulnerability

Coordinated disclosure, 90-day standard window. Hall of fame for verified reports.

security.txt →

Or email security@plutobee.com (PGP key on request).

Vendor security review

SIG Lite, CAIQ Lite, and HECVAT Lite responses prepared. We can usually return a full questionnaire in 5 business days.

Request the package →

Need the full DPA, security package, or a signed audit letter?

Talk to our trust team →

Want to walk through this live?

Book a 25-minute call with a senior engineer. No prep needed. We will share notes and a written summary after.

Start a project