We know your data is extremely important to you and your business, and we’re very protective of it. Our data is stored on PlaidCloud too. We take specific precautions to protect your data and ensure security. We employ defense in depth to keep data secure and private.
PlaidCloud utilizes certified data centers managed by Google. Google has many years of experience in designing, constructing, and operating large-scale data centers. Google designs and builds its own data centers, which incorporate multiple layers of physical security protections. Access to these data centers is limited to only a very small fraction of Google employees. Google uses multiple physical security layers to protect data center floors and uses technologies like biometric identification, metal detection, cameras, vehicle barriers, and laser-based intrusion detection systems.
Google only provides data center access and information to employees who have a legitimate business need for such privileges. When an employee no longer has a business need for these privileges, his or her access is immediately revoked, even if they continue to be an employee of Google. All physical and electronic access to data centers by Google employees is logged and audited routinely.
For additional information see: https://cloud.google.com/security/infrastructure/design
Workflows execute within their own isolated environment and cannot interact with other workflows. In addition, they have limited communication policies enforced by Kubernetes networking policies providing an additional layer of security. This restrictive operating environment ensures isolation of user defined code and expressions.
All system configurations and deployments utilize automated deployment processes defined by Kubernetes and Helm. Manual changes are not permitted and actively rolled back automatically. PlaidCloud relies on a very automated self-healing compute environment that limits human interaction and access to systems. This not only ensures security policies are enforced automatically but also prevents circumventing of security processes.
The PlaidCloud team of specialists are available 24/7/365 to keep our software and its dependencies updated, eliminating potential security vulnerabilities. Our software engineers review each line of code before deploying it to our production environment. They are trained to search for and solve security vulnerabilities. We employ a wide range of monitoring solutions for preventing and eliminating attacks. In addition, we employ all of Google’s threat detection and mitigation tools along with a focus on eliminating all possible attack vectors by reducing attack surface area.
All data exchanged with PlaidCloud is transmitted over encrypted connections to maintain end-to-end security. All communication with PlaidCloud occurs over HTTPS using modern SSL and TLS processes. We do not accept connections that are not encrypted.
User access is controlled by the implementation of multiple authentication processes including single sign-on, OpenID, Multi-Factor, and password. The method of authentication can be determined by the Workspace or individual.
PlaidCloud employees never access private workspace data unless such access is required for support reasons. Support staff may sign in to your account to access settings related to your support issue. In rare cases, staff may need to pull a clone of your data, but this is only done with your consent. Support staff does not have direct access to copy or view any data. When working on a support issue, we respect your privacy as much as possible, accessing only the files and settings needed to resolve your issue. All copied data is deleted as soon as the support issue is resolved.
We do not store or process credit card, purchasing card, debit card, or ACH account information. We utilize Stripe for all payments to ensure security of your payment information. We also support direct invoicing for enterprise customers.
Please submit a PlaidCloud Responsible Vulnerability Disclosure report through the help page. We will make every attempt to address the issue as quickly as possible.
| Cookie | Duration | Description |
|---|---|---|
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |