> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plomo.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Plomo Compliance: GDPR, SOC 2, ISO 27001, and Data Residency

> How Plomo aligns with GDPR, SOC 2, and ISO 27001 requirements, where your data is stored, and how to request an enterprise security review.

Plomo's infrastructure and operating practices are designed to support teams with compliance requirements in regulated environments. This page covers Plomo's alignment with GDPR, the certifications held by the infrastructure providers Plomo builds on, data residency options, and how to engage Plomo's team for enterprise security reviews.

## GDPR

Plomo is built with GDPR principles applied across the data lifecycle. Key practices include:

| Principle             | How Plomo addresses it                                                                                                                                                        |
| --------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Data minimization** | Plomo processes only the content needed for each workflow step — documents are ingested for classification, retrieval, and CIM drafting; no extraneous data collection occurs |
| **Access control**    | Deal membership gates all data access at the application layer, and row-level security at the database layer provides an independent enforcement boundary                     |
| **Encryption**        | Per-deal encryption keys protect uploaded documents and all rich content fields; see the [Encryption](/security/encryption) page for details                                  |
| **Retention**         | Documents and deal content are tied to the deal workspace lifecycle — data is not retained beyond the operational purpose of the deal                                         |

If you have specific GDPR questions — including data processing agreements (DPAs), subprocessor lists, or data subject request handling — contact **[admin@plomo.ai](mailto:admin@plomo.ai)**.

## SOC 2

Plomo's production infrastructure is hosted on providers that maintain **SOC 2 Type II** certification, covering the Trust Service Criteria for security, availability, and confidentiality. This includes Plomo's hosting provider, managed inference provider, and edge security provider.

Plomo's per-deal encryption is applied on top of provider-level encryption, providing an additional layer of data protection beyond what the SOC 2 certifications cover at the infrastructure level.

## ISO 27001

Plomo's hosting, inference, and edge security providers maintain **ISO 27001** certification, demonstrating a structured information security management system (ISMS). Enterprise customers requiring ISO 27001 coverage as part of vendor qualification can reference these certifications in their security reviews.

Plomo supports enterprise security reviews — see below for how to engage.

## Data Residency

| Instance                           | Region             | Data location                                    |
| ---------------------------------- | ------------------ | ------------------------------------------------ |
| **EU production** (`app.plomo.ai`) | Frankfurt, Germany | All customer data stored and processed in the EU |
| **US instance**                    | North America      | Coming soon                                      |

The EU production instance is appropriate for teams with European data residency requirements under GDPR or contractual obligations to keep deal data within the EU.

## Analytics and Event Metadata

Plomo may collect **event-level metadata** — for example, reclassification events or low-confidence classification results — to improve accuracy and model performance over time. This data is operational metadata about how the product is being used.

Plomo does **not** collect or use raw document bodies for analytics purposes. Document content remains scoped to deal workflows and is not surfaced in any analytics pipeline.

## Security Reviews for Enterprise Customers

Enterprise customers can request additional documentation and detail on any of the following topics:

* Architecture overview and data flow diagrams
* Subprocessor list and data processing agreements
* Access control model and personnel access policies
* Data retention and deletion procedures
* Incident response process
* Penetration test summaries (under NDA)

To initiate a security review, contact **[admin@plomo.ai](mailto:admin@plomo.ai)** with your organization name and the scope of your review requirements. Plomo's team will respond with the appropriate materials and arrange a technical call if needed.
