GDPR
Plomo is built with GDPR principles applied across the data lifecycle. Key practices include:
If you have specific GDPR questions — including data processing agreements (DPAs), subprocessor lists, or data subject request handling — contact [email protected].
SOC 2
Plomo’s production infrastructure is hosted on providers that maintain SOC 2 Type II certification, covering the Trust Service Criteria for security, availability, and confidentiality. This includes Plomo’s hosting provider, managed inference provider, and edge security provider. Plomo’s per-deal encryption is applied on top of provider-level encryption, providing an additional layer of data protection beyond what the SOC 2 certifications cover at the infrastructure level.ISO 27001
Plomo’s hosting, inference, and edge security providers maintain ISO 27001 certification, demonstrating a structured information security management system (ISMS). Enterprise customers requiring ISO 27001 coverage as part of vendor qualification can reference these certifications in their security reviews. Plomo supports enterprise security reviews — see below for how to engage.Data Residency
The EU production instance is appropriate for teams with European data residency requirements under GDPR or contractual obligations to keep deal data within the EU.
Analytics and Event Metadata
Plomo may collect event-level metadata — for example, reclassification events or low-confidence classification results — to improve accuracy and model performance over time. This data is operational metadata about how the product is being used. Plomo does not collect or use raw document bodies for analytics purposes. Document content remains scoped to deal workflows and is not surfaced in any analytics pipeline.Security Reviews for Enterprise Customers
Enterprise customers can request additional documentation and detail on any of the following topics:- Architecture overview and data flow diagrams
- Subprocessor list and data processing agreements
- Access control model and personnel access policies
- Data retention and deletion procedures
- Incident response process
- Penetration test summaries (under NDA)