Security at Pleaxy
Procurement data is financial data. Here is how we protect it today, and where we are on the road to independent certification.
Last updated October 4, 2026
App security
What protects your purchase orders, invoices, supplier records and approvals inside Pleaxy today. We describe only controls that are running in production — see Not yet in place for what we don't do yet.
Infrastructure and hosting
Pleaxy runs on Amazon Web Services in the US East (N. Virginia) region. The backend is serverless — Amazon API Gateway, AWS Lambda and Amazon DynamoDB — and the app and this site are served from Amazon S3 through Amazon CloudFront.
Every request is subject to an API-wide rate limit, and invoice feeds and the in-app assistant have their own per-key and daily limits to contain abuse.
Sign-in and sessions
- Accounts are managed by Amazon Cognito. Sign-in uses the Secure Remote Password protocol, so your password is never sent to or stored by Pleaxy's servers.
- Email addresses are verified at sign-up, and passwords must be at least 8 characters with upper-case, lower-case and a digit.
- Any user can turn on 2-Step Verification with an authenticator app. It is optional, not enforced, and we don't offer text-message codes.
- Every API request's access token is verified cryptographically, and your workspace membership is re-checked on each request — so when an administrator removes someone, they lose access to the workspace on their very next request, not when their token expires.
- API keys are revoked automatically too: when an administrator removes someone, or changes their role from Administrator to another role, every API key that person created in the workspace is revoked as part of the same change, and the administrator making the change is told which keys were revoked.
Workspace isolation
Each company works in its own workspace. Every record is stored under its workspace's key, and every request is checked server-side against the caller's workspace membership before any data is read or written. Two things are shared by design: purchase orders and invoices are visible to both trading parties, and buyers inviting suppliers can find verified supplier profiles (company name, contact email and the names of the workspaces the supplier is active in).
Roles and permissions
Buyer workspaces have six procurement roles — Administrator, Read-only, Contracts & suppliers, Relationships, Requisitions and Finance — each of which grants no access, view, create or edit access to each module. Permissions are enforced by the API, not just hidden in the interface. Supplier workspaces use a simpler administrator and member model.
Approval controls
- Every approval step is assigned to a specific person, and only that person can approve or reject it. A step with no one assigned waits until an administrator assigns someone.
- An API key can never approve or reject an approval step. It also can't change approval chains, automation rules, auto-approval thresholds or spend limits — only a signed-in person can. An integration can raise purchase orders and invoices, but whether they need a human approver is decided only by the rules your team sets.
- Purchase orders and invoices can still be approved automatically if your administrators turn on automation rules, or administrators or Finance users set an auto-approval threshold. Those approvals are recorded as automatic.
- Every approve, reject, reassign or skip is kept in the document's approval history with who (or which automation) did it and when.
- A requester can approve their own request only when they are the sole eligible approver, and that is recorded as a self-approval. A company cannot raise purchase orders or invoices with itself.
API keys and AI agents
- API keys are generated from 32 random bytes and shown once. We store only a keyed hash (HMAC-SHA256), never the key itself, and compare it in constant time.
- Each key belongs to one workspace and one role — supplier keys also carry explicit scopes — and can be revoked at any time. Only a signed-in administrator can create or revoke keys; a key cannot mint another key. A person's keys are revoked automatically when they're removed from the workspace or stop being an administrator, and re-adding them doesn't restore a revoked key.
- The Pleaxy MCP server, which lets AI agents call Pleaxy, uses the same API and the same scoped key. It gets no extra privileges.
Encryption
- In transit: HTTPS only. Plain HTTP is redirected, storage refuses unencrypted connections, and browsers are told to use HTTPS for every visit (HSTS) alongside AWS's standard security headers.
- At rest: databases, file storage, queues and secrets are all encrypted with AWS-managed keys.
Secrets and cloud-billing connections
Application secrets live in AWS Secrets Manager and Systems Manager Parameter Store — never in source code or deployment configuration.
Every cloud billing connection is read-only, created in your own account, and revocable from your own console. We never ask for your cloud passwords or access keys. On AWS you create a billing role with an External ID unique to the connection, and Pleaxy assumes it. Google Cloud and Microsoft Azure use federated sign-in, so no secret is stored. For Oracle Cloud Infrastructure (OCI), Pleaxy generates an API signing key for the connection and you upload only its public key; the private key is stored only encrypted with AWS KMS, and deleting the key in Oracle revokes access. Billing data already imported stays in your workspace until deleted.
Supplier documents
Tax forms, insurance certificates and bank letters are kept in a private storage bucket and are only reachable through short-lived, signed links. Deleting a document erases every stored version of it.
AI assistant
- The in-app assistant runs on Anthropic's Claude through Amazon Bedrock, called from our own AWS account in the US East region.
- Pleaxy does not keep chat transcripts. An action the assistant proposes is held briefly so you can confirm it.
- The assistant acts as the signed-in user, with exactly their permissions. Approvals, recorded payments, discrepancy resolutions and automation-rule changes are only proposed — a person confirms each one with a button. The assistant can also reject a document, create a purchase order, turn one into an invoice, re-run invoice matching or send a reminder without a separate confirmation step — it is instructed to do so only when you ask, so review what it tells you it is about to do.
Logging, monitoring and backups
- An account-wide AWS CloudTrail audit trail records every AWS management API call, with log-file integrity validation, kept for 365 days in a bucket whose policy denies deletion. Changes to the trail or that policy raise an alert.
- Automated alarms watch for API errors and latency, failed jobs and failed billing syncs, with a separate channel for security alerts.
- Production databases have point-in-time recovery and deletion protection, and document storage is versioned.
- API access logs are kept for 30 days and application logs for 90 days.
Not yet in place
So your security review has the full picture, these are on our roadmap but not live today:
- Enforced multi-factor sign-in, passkeys, single sign-on (SAML/OIDC) and SCIM provisioning.
- A web application firewall and a Content Security Policy.
- AWS GuardDuty and Security Hub, and a production AWS account separate from the one we administer the organisation from.
- An independent penetration test.
Reporting a vulnerability
If you believe you've found a security issue in Pleaxy, email support@pleaxy.ai with the details. Please give us a reasonable chance to fix it before disclosing it publicly.
Compliance
Pleaxy is an early-stage company. We have not yet completed a third-party security audit — the controls above are what we run today, and we're glad to complete your security questionnaire.
GDPR and UK GDPR
GDPR is a law, not a certificate, and we build Pleaxy to meet it. For the data you put into your workspace — employees, suppliers, purchase orders, invoices and documents — you are the controller and Pleaxy is your processor, acting only on your instructions. For account, billing and website data, Pleaxy is the controller.
- Data Processing Agreement: we are finalising our standard DPA, with our sub-processor list, the security measures on this page and the transfer clauses below. Email us if you need one.
- Where data lives: in the United States (AWS US East). Transfers of EU and UK personal data will be covered by the EU Standard Contractual Clauses and the UK Addendum in our DPA.
- Your rights: access, correction and deletion requests are handled on request — see our Privacy Policy.
US privacy laws
We do not sell personal information or “share” it for cross-context behavioural advertising, as California law defines those terms, and the Pleaxy website uses no advertising or analytics trackers.
Card payments
Pleaxy never handles your card details. Subscription payments are processed on Stripe's hosted pages, and Stripe is a PCI DSS Level 1 service provider.
Certifications roadmap
We'll pursue independent certification in this order, and update this page as each one lands:
- SOC 2 Type I — planned. The standard security audit for US B2B software.
- SOC 2 Type II — planned, following Type I. Confirms controls work over months, not just on one day.
- ISO/IEC 27001 — planned, for customers in the EU and UK that require it.
Until then, we answer security questionnaires (including SIG Lite and CAIQ) directly — email support@pleaxy.ai.