Legal

Security

Last updated: 3 June 2026

Draft — pending legal review

This document is a structural scaffold. The wording must be reviewed and finalised by legal counsel before launch.

An overview of how Plumb protects data. [REVIEW: confirm specifics with counsel / security lead before publishing as commitments.]

Data residency

Customer data is hosted in the UK/EEA (Supabase eu-west-2, London) with EU edge delivery.

Encryption

Data is encrypted in transit (TLS) and at rest. [REVIEW: confirm at-rest details.]

Access control

Access is governed by row-level security (RLS) at the database layer, scoped per organisation and role. Anonymous shortlisting is enforced server-side, not in client code.

Audit logging

Mutations emit immutable audit events; update and delete are revoked from the application role. Only the service role can mutate audit data, and only for audit-logged GDPR erasure.

Backups and availability

[REVIEW: backup cadence, retention, and recovery objectives.]

Responsible disclosure

[REVIEW: security contact and disclosure policy.]