Skip to main content
Plomo provides technical controls for protecting deal data, including organization and deal authorization, database row-level security, private storage, and application encryption. Your security review should consider those controls together with the deployment configuration, subprocessor terms, and the agreement for your organization.

Data protection review

The security overview and encryption guide describe the implemented controls. For GDPR and other data protection requirements, contact [email protected] to review:
  • The data processing agreement and each party’s responsibilities.
  • The current subprocessor list and the data each service processes.
  • Retention periods, deletion procedures, backups, and legal holds.
  • Data subject requests and incident notification arrangements.
Technical controls support this review; the applicable legal and contractual requirements depend on your organization’s use of the service.

Data residency

The EU deployment configuration separates application hosting, storage, and AI processing: EU residency mode rejects OpenRouter and Bedrock generation routes and non-EU Vertex locations. Azure model routes require the EU Data Zone configuration. This inference policy does not establish an EU-only boundary for every service used by the product. Identity, web research, sandbox execution, analytics, and operational services have separate processing terms and locations. Request the current deployment and subprocessor evidence before relying on a specific residency commitment. Additional regional deployments require a separate agreement.

AI data handling

Plomo sends content to model providers to perform the requested document, retrieval, and drafting workflows. Azure requests disable Responses API persistence with store: false. Response persistence, abuse-monitoring retention, model training, and geographic processing are separate provider controls. Disabling response storage does not by itself establish zero data retention. Confirm the current provider terms and any approved retention exceptions as part of your review.

Retention and deletion

Retention covers more than the active deal workspace. Object versions, temporary uploads, generated artifacts, database backups, logs, and provider-held data each have a separate lifecycle. The cloud storage configuration includes cleanup rules for temporary uploads and design checkpoints; those rules do not define a single retention period for all customer data. Agree the required deletion scope and retention schedule with Plomo, including backup expiry and any legal hold requirements.

Certifications and independent assurance

A provider’s SOC 2 report or ISO 27001 certificate covers the services and scope named in that evidence. It does not establish that Plomo itself holds the same certification, or that every service in a deployment is covered. For vendor qualification, request current assurance materials with their dates, scope, and applicable services. Plomo-specific certifications, audit results, and penetration-test evidence should be confirmed directly during that review.

Enterprise security reviews

Contact [email protected] with your organization name and review requirements. Relevant topics include architecture and data flows, access control, key management, subprocessors, retention, incident response, and available independent testing evidence.