Docs

Security — full reference

Reference for Plugsky security: encryption at rest and in transit, authentication via API keys or SSO, RBAC, audit logs, customer-managed keys (BYOK), and compliance attestations (SOC 2, ISO 27001, HIPAA, GDPR, PDPL).

Encryption

Layer Method
At restAES-256 with envelope encryption (per-region KMS)
In transitTLS 1.3 only, HSTS preloaded
Customer-managed keys (BYOK)AWS KMS, Azure Key Vault, HashiCorp Vault, on-prem HSM
Per-request encryptionOptional for highly regulated workloads
Zero-knowledge modeYour gateway encrypts before sending; model never sees plaintext

Authentication

Method Notes
API keysBearer token in Authorization header. sk-live-... for live, sk-test-... for sandbox.
SAML 2.0 SSOEnterprise. Entra ID, Okta, Google Workspace, Ping, ADFS.
OIDCAny OIDC-compliant IdP.
SCIM provisioningEnterprise. Auto-provision and de-provision users from your IdP.
mTLSEnterprise. Client certificate authentication for service-to-service.

Audit logs

Every request is logged with: timestamp, model, prompt hash, completion hash, token count, latency, IP, user ID, region. Audit logs are exportable to your SIEM (Splunk, Sentinel, QRadar, Datadog) and retained for the period you choose (default 90 days, up to 7 years on Enterprise).

Compliance

  • SOC 2 Type II — security, availability, confidentiality
  • ISO 27001 / 27017 / 27018
  • HIPAA + BAA available
  • GDPR + EU SCCs available
  • PDPL (Saudi, UAE, Qatar, Bahrain, Kuwait, Oman)
  • FedRAMP Moderate (Q4 2026)
  • DIFC DPL + NSD + SAMA + CBUAE + QCB + CBB + CBO aligned

Frequently asked questions

How do I get a SOC 2 Type II report?

Enterprise customers can request the SOC 2 Type II report under NDA from your account manager or via security@plugsky.com.

Is BYOK available on self-serve?

BYOK is Enterprise-only. Self-serve uses Plugsky-managed KMS per region. Contact sales for Enterprise BYOK.

How do I enable SAML SSO?

Enterprise customers: Settings → Authentication → SAML SSO. We support Entra ID, Okta, Google Workspace, Ping, ADFS, and any SAML 2.0-compliant IdP.

What about responsible disclosure?

Email security@plugsky.com. PGP key on request. We respond within 24h and credit researchers in our hall of fame.

Get the security overview

SOC 2, ISO 27001, BYOK, audit logs. Standard on Enterprise.

See security overview → See data residency