Skip to content
Return home

Security

Effective Date:
Last Updated:

Security at a Glance

  • Hosted in the United States using third-party hosting and cloud infrastructure providers, which manage physical data-center security
  • Customer Data encrypted in transit using TLS 1.2 or higher and encrypted at rest using industry-standard encryption
  • Authentication controls appropriate to enterprise deployments, including single sign-on available upon request
  • Internal access to Customer Data restricted according to least privilege; administrative access to production systems logged where supported
  • Plasma AI does not use Customer Data to train or improve artificial intelligence or machine learning models
  • Customer Data logically segregated using application, database and access controls
  • Production Customer Data backed up automatically on a configured schedule, with backups encrypted at rest
  • Customers notified within 72 hours of confirmed security breaches affecting their Customer Data
  • Customer Data exportable during the subscription and deleted following applicable retrieval and retention periods
  • SOC 2 Type II examination process initiated with an independent auditor

The sections below describe in greater detail the administrative, physical and technical safeguards that Plasma AI Inc. (“Plasma AI,” “we,” or “us”) maintains to protect Customer Data. This page is the Security Page referenced in Section 2.2 of the Plasma AI Customer Agreement. Capitalized terms used but not defined on this page have the meanings given in the Customer Agreement.

1. Our Approach to Security

Plasma AI maintains a security program materially in accordance with industry standards that is designed to (i) ensure the security and integrity of Customer Data; (ii) protect against threats or hazards to the security or integrity of Customer Data; and (iii) prevent unauthorized access to Customer Data. Security is foundational to how we build and operate our products, and our practices are designed to scale with our customers’ requirements.

2. Infrastructure and Physical Security

The Plasma AI Product is hosted in the United States using third-party hosting and cloud infrastructure providers identified in Plasma AI’s subprocessor list. Plasma AI does not operate its own data centers. Physical security for the underlying infrastructure is managed by our hosting providers, whose security programs include physical access controls, monitoring, environmental safeguards and independent security assessments. Access to Plasma AI’s offices is restricted to authorized personnel. Customer Data is not stored on physical media in our offices.

3. Encryption

Customer Data transmitted over public networks between customers and the Plasma AI Product is encrypted using TLS 1.2 or higher. Customer Data stored by Plasma AI in production databases, object storage and backups is encrypted at rest using industry-standard encryption. Access to cryptographic keys and related configuration is restricted through provider key-management and access controls.

4. Access Controls

System access. Interactive access to Plasma AI’s production systems is limited to authorized personnel using unique, individually assigned accounts protected by multi-factor authentication. Authentication is federated through individual identity accounts where supported and otherwise managed directly through the applicable infrastructure provider. Access rights are granted according to role and operational need and are revoked promptly when no longer required. Shared accounts are not permitted for interactive production access.

Access to Customer Data. Internal access to Customer Data is restricted to authorized personnel when reasonably necessary to provide, secure, maintain or support the Plasma AI Product. Administrative access to production systems is logged where supported by the relevant system.

Customer authentication. The Plasma AI Product supports authentication controls appropriate to enterprise deployments, including single sign-on available upon request.

5. Logging and Monitoring

Plasma AI maintains application and infrastructure logs appropriate to the operation and security of the Plasma AI Product. Depending on the relevant system, logs may record authentication events, administrative access, configuration changes, data-transfer operations and material changes to Customer Data, together with information such as the responsible account, timestamp, action and outcome.

Access to logs is restricted to authorized personnel. Logs are retained in accordance with documented retention practices and are protected through access controls designed to prevent unauthorized modification or deletion. Plasma AI monitors production systems for anomalous activity and security events and uses relevant logs to support security investigations and incident response.

6. Data Segregation

Customer Data is logically segregated using application, database and access controls designed to prevent unauthorized access between customers. Production, testing and development environments are maintained separately. Production Customer Data is not copied into or used in testing or development environments, except with the customer’s authorization or after the data has been appropriately de-identified.

7. Availability, Backups and Business Continuity

The Plasma AI Product is hosted on infrastructure designed to support service resilience, with redundancy deployed where appropriate. Production Customer Data is backed up automatically on a configured schedule, and backups are encrypted at rest. Plasma AI maintains business continuity and disaster recovery procedures designed to restore service and data following an interruption. Backup restoration procedures are tested periodically.

Plasma AI and its hosting providers maintain network, endpoint and malware-protection controls appropriate to the systems and services they operate.

8. Application and Network Security

Plasma AI follows secure development practices, including review of production code changes and risk-based patching of dependencies and systems. Network access controls, private networking and provider-managed protections restrict access to production systems based on operational need. Interactive administrative access to production systems is limited to authorized personnel, uses encrypted connections, and requires multi-factor authentication.

9. AI Models and Customer Data

Plasma AI does not use Customer Data, including Personal Data contained therein, to train or improve artificial intelligence or machine learning models. Customer Data submitted to the Plasma AI Product is processed as necessary to provide, secure, maintain and support the product and as otherwise permitted by the Customer Agreement.

Customers may configure the Plasma AI Product to use models, cloud accounts, compute environments or other resources that they procure or control (“Customer-Provided Resources”). To provide these integrations, Plasma AI may receive and use credentials or delegated permissions and may transmit Customer Data to, execute operations within, or receive results from Customer-Provided Resources as directed by the customer. Plasma AI limits its use of such credentials and permissions to providing the Plasma AI Product, collecting operational and usage information, supporting the customer when requested, and maintaining security.

Except for automated processing necessary to provide the Plasma AI Product, authorized Plasma AI personnel do not access content within Customer-Provided Resources unless reasonably necessary to provide requested support, investigate a security or reliability issue, comply with law, or as otherwise authorized by the customer. A customer’s use of Customer-Provided Resources is also subject to the customer’s agreements and configurations with the applicable provider.

10. Subprocessors and Third Parties

Plasma AI uses a number of third-party service providers to help provide the Plasma AI Product, such as cloud hosting and third-party model providers. Before engaging a subprocessor that will process Customer Data, we evaluate its security practices and bind it to contractual obligations protective of Customer Data. The current list of subprocessors is set out in our Data Processing Addendum, available at plasma.ai/dpa.

11. Personnel Security

All Plasma AI personnel are bound by confidentiality obligations. Personnel receive security and privacy training on hire and periodically thereafter. Plasma AI performs background checks on new hires where permitted by applicable law.

12. Incident Response and Breach Notification

Plasma AI maintains incident response procedures for identifying, containing, investigating and remediating security incidents. If Plasma AI becomes aware of a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data, Plasma AI will notify affected customers without undue delay and, in any event, within 72 hours after becoming aware that the breach affected Customer Data. Plasma AI will provide information reasonably available to it to assist affected customers in meeting applicable notification obligations.

13. Data Retention and Deletion

Customers may export Customer Data during their subscription using the Plasma AI Product’s then-current export functionality or by submitting a request to Plasma AI. Following expiration or termination, Customer Data will remain available for retrieval for up to thirty (30) days, subject to the Customer Agreement. Plasma AI will then delete Customer Data from active systems, except where retention is required by law. Copies maintained in backups will expire according to Plasma AI’s documented backup-retention schedules and will remain protected under the Customer Agreement until deletion.

14. Compliance

Plasma AI has initiated a SOC 2 Type II examination process with an independent auditor. Upon completion, our SOC 2 report will be available to customers under NDA. We will update this page as our compliance certifications progress.

15. Contact

Questions about this page or Plasma AI’s security practices, and reports of suspected vulnerabilities or security incidents, can be sent to security@plasma.ai.