Skip to main content
M&A due diligence involves some of the most sensitive documents your organization handles — financial statements, customer contracts, IP filings, and employee data. Plomo is built from the ground up with that sensitivity in mind. Every deal is isolated at multiple layers of the stack, documents are encrypted with deal-specific keys, and nothing you upload is ever used to train AI models. This page summarizes the core security properties underpinning the platform.

Core Security Properties

Production Infrastructure

Plomo’s EU production environment (app.plomo.ai) runs in Frankfurt, Germany, supporting European data residency requirements. All customer data — documents, deal content, and chat sessions — is stored and processed within this region. A US instance is coming soon for teams that require North American data residency.

Edge Security

Plomo’s edge network is provided by Cloudflare, using HTTP/3 for all connections between end-users and the platform. Cloudflare’s Web Application Firewall (WAF) and DDoS mitigation layer sit in front of every request, filtering malicious traffic before it reaches the application.

Dig Deeper

Encryption

Per-deal envelope encryption, what fields are encrypted, in-transit security, and the enterprise BYOK option.

Compliance

GDPR alignment, SOC 2 and ISO 27001 provider certifications, data residency details, and how to request a security review.

Report a Vulnerability

If you discover a potential security issue in Plomo, please report it responsibly by emailing [email protected]. We review all reports promptly and will work with you to understand and address the issue.