Skip to main content
Plomo protects deal documents and the work you create from them through organization-scoped access, database policies, and application encryption. These controls apply across document processing, Dealmate conversations, and CIM drafting.

Access and isolation

Encryption and authorization work together: Plomo decrypts content for authorized product workflows, including AI processing. See Encryption for the fields covered and the key lifecycle.

AI processing and data location

The EU deployment configuration uses Google Cloud services in Frankfurt and document storage in the EU multi-region. AI processing uses Azure OpenAI EU Data Zone deployments for Dealmate and CIM, and Vertex AI EU endpoints for document processing, embeddings, and reranking. The runtime rejects unsupported providers and non-EU model locations when EU residency mode is enabled. AI inference location is one part of data residency. Identity, web research, sandbox execution, analytics, and other subprocessors have their own processing boundaries. Compliance and security reviews explains how to confirm the full scope for your organization.

Transport and edge protection

The cloud deployment configures HTTPS through Cloudflare and Google’s load balancer, with TLS to the origin. TLS 1.3 and HTTP/3 are enabled at the edge where supported by the client and network. The origin access policy restricts public load-balancer traffic to Cloudflare’s network.

Learn more

Encryption

Protected content, encrypted uploads, and customer-managed wrapping keys.

Compliance and security reviews

Data residency, retention, provider assurance, and enterprise review materials.

Report a vulnerability

Report a potential security issue to [email protected]. Include the affected feature, steps to reproduce, and the impact you observed. Avoid including live credentials or customer documents in the initial report.