Skip to main content
Plomo’s infrastructure and operating practices are designed to support teams with compliance requirements in regulated environments. This page covers Plomo’s alignment with GDPR, the certifications held by the infrastructure providers Plomo builds on, data residency options, and how to engage Plomo’s team for enterprise security reviews.

GDPR

Plomo is built with GDPR principles applied across the data lifecycle. Key practices include: If you have specific GDPR questions — including data processing agreements (DPAs), subprocessor lists, or data subject request handling — contact [email protected].

SOC 2

Plomo’s production infrastructure is hosted on providers that maintain SOC 2 Type II certification, covering the Trust Service Criteria for security, availability, and confidentiality. This includes Plomo’s hosting provider, managed inference provider, and edge security provider. Plomo’s per-deal encryption is applied on top of provider-level encryption, providing an additional layer of data protection beyond what the SOC 2 certifications cover at the infrastructure level.

ISO 27001

Plomo’s hosting, inference, and edge security providers maintain ISO 27001 certification, demonstrating a structured information security management system (ISMS). Enterprise customers requiring ISO 27001 coverage as part of vendor qualification can reference these certifications in their security reviews. Plomo supports enterprise security reviews — see below for how to engage.

Data Residency

The EU production instance is appropriate for teams with European data residency requirements under GDPR or contractual obligations to keep deal data within the EU.

Analytics and Event Metadata

Plomo may collect event-level metadata — for example, reclassification events or low-confidence classification results — to improve accuracy and model performance over time. This data is operational metadata about how the product is being used. Plomo does not collect or use raw document bodies for analytics purposes. Document content remains scoped to deal workflows and is not surfaced in any analytics pipeline.

Security Reviews for Enterprise Customers

Enterprise customers can request additional documentation and detail on any of the following topics:
  • Architecture overview and data flow diagrams
  • Subprocessor list and data processing agreements
  • Access control model and personnel access policies
  • Data retention and deletion procedures
  • Incident response process
  • Penetration test summaries (under NDA)
To initiate a security review, contact [email protected] with your organization name and the scope of your review requirements. Plomo’s team will respond with the appropriate materials and arrange a technical call if needed.