Trust & compliance

How does Plugsky protect customer data and infrastructure?

Plugsky's security program combines AES-256 encryption at rest, TLS 1.3 in transit, SAML/OIDC SSO, SCIM, RBAC, BYOK with HSM-backed key custody, audit-log export to your SIEM and a responsible-disclosure program. Documented compliance programs include SOC 2 Type II, ISO 27001/27017/27018, HIPAA with BAA and GDPR; FedRAMP Moderate is in process.

Key facts

EncryptionAES-256 at rest with envelope encryption; TLS 1.3 only in transit
CertificationsSOC 2 Type II; ISO 27001, 27017, 27018
Privacy and healthGDPR with EU SCCs; HIPAA with BAA available; PDPL alignment
Key custodyBYOK via AWS KMS, Azure Key Vault, HashiCorp Vault or on-prem HSM
Access controlSAML 2.0 / OIDC SSO and SCIM on Enterprise; workspace, role and resource RBAC
Audit logsExport to Splunk, Sentinel, QRadar or Datadog
DisclosureResponsible disclosure program with a published security contact
FedRAMPModerate in process (targeted Q4 2026)

TL;DR

  • Encryption covers data at rest and in transit by default.
  • SSO, SCIM and BYOK are Enterprise controls; RBAC and audit logs are broader.
  • SOC 2 Type II and ISO programs are documented; reports are shared under NDA.
  • FedRAMP Moderate is in process — do not treat it as granted.
  • Vulnerability reports go through a public disclosure program.

How it works, step by step

  1. Inventory the data classes and regions your AI workload touches.
  2. Enable workspace RBAC and issue scoped keys for each application.
  3. Configure SSO and SCIM provisioning if you are on Enterprise.
  4. Turn on BYOK or zero-knowledge mode for regulated data.
  5. Export audit logs to your SIEM and define retention and alerting.
  6. Request the SOC 2 Type II report and map controls to your own framework.
1Inventory the dataclasses and regionsyour AI workload2Enable workspaceRBAC and issuescoped keys for3Configure SSO andSCIM provisioningif you are on4Turn on BYOK orzero-knowledge modefor regulated data.5Export audit logsto your SIEM anddefine retention6Request the SOC 2Type II report andmap controls to

Original data

AES-256 at resEncryptionSOC 2 Type II;CertificationsSAML 2.0 / OIDAccess controlModerate in prFedRAMPSource: Plugsky facts table · updated 2026-09-26

Try it yourself

Open the sovereign AI readiness scorecard →

Certifications and what they cover

Plugsky documents SOC 2 Type II across security, availability and confidentiality, plus ISO 27001 for information security management, ISO 27017 for cloud-specific controls and ISO 27018 for PII protection. HIPAA with a BAA is available, GDPR is supported with EU SCCs, and PDPL alignment is documented for Saudi Arabia. The SOC 2 Type II report is provided to customers under NDA rather than published, which is standard practice.

Where the program is still maturing: FedRAMP Moderate is in process with a targeted Q4 2026 milestone on the live page. Until authorization is granted, federal workloads should not assume it.

Encryption and key custody

Data at rest uses AES-256 with envelope encryption and per-region KMS keys. Traffic is TLS 1.3 only with HSTS preloaded. Customers who need their own key custody can use BYOK through AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM; optional per-request encryption and zero-knowledge mode go further for highly regulated workloads. Key lifecycle operations — rotation, revocation and audit — remain with you under BYOK.

Identity, access and audit

Authentication starts with bearer API keys that carry roles and scopes: read, infer and admin. Enterprise adds SAML 2.0 and OIDC SSO for people, SCIM for lifecycle provisioning and mTLS for service-to-service traffic. RBAC operates at workspace, role and resource level, and per-key rate limits contain the blast radius of a leaked credential.

Every key action is logged with actor, timestamp, IP and request hash, and logs export to Splunk, Sentinel, QRadar or Datadog. Retention is configurable, with long retention available on Enterprise.

Responsible disclosure and incident readiness

Researchers can report vulnerabilities through the published security contact, with a PGP key available on request; reports are acknowledged and credited through the disclosure program. On the operations side, incident response runs against defined P1, P2 and P3 targets, and status is published on the status page with incident history. Quarterly penetration tests and an external review program back the controls.

For buyers: request the current reports, verify the sub-processor list and confirm the residency topology that applies to you. Paper controls only help if the deployment actually matches them.

Honest comparison

AreaPlugskyTypical AI API vendorSelf-hosted open-source stack
Encryption defaultsAES-256 at rest, TLS 1.3 in transitUsually comparableYou configure
Key custodyBYOK with KMS or HSMOften vendor-managedYou own
Enterprise identitySAML, OIDC, SCIM, mTLSVariesYou integrate
Audit loggingRequest and key-action logs with SIEM exportVariesYou build
Certification reportsSOC 2 Type II and ISO programsVariesYou certify yourself
Deployment optionsCloud, VPC, on-prem, air-gappedMostly SaaSOn-prem only

Frequently asked questions

Is Plugsky SOC 2 Type II certified?

Plugsky documents a SOC 2 Type II program covering security, availability and confidentiality, and shares the report with customers under NDA; request it through your account team.

What ISO certifications does Plugsky hold?

ISO 27001 for information security management, ISO 27017 for cloud controls and ISO 27018 for PII protection are documented on the security page.

How does BYOK work?

You import keys from AWS KMS, Azure Key Vault, HashiCorp Vault or an on-prem HSM. Plugsky cannot read data encrypted with keys you control, and rotation and revocation stay with you.

Do you offer a BAA for healthcare?

Yes. HIPAA with a BAA is available, and healthcare deployments can run in region-locked or private environments.

What is the breach notification commitment?

The DPA commits to notification within 72 hours, in line with GDPR Article 33.

Can I get an audit report?

SOC 2 Type II reports are available under NDA. ISO reports and penetration-test summaries are shared during vendor reviews on request.

Is FedRAMP authorization complete?

No. FedRAMP Moderate is in process with a targeted Q4 2026 milestone; verify status with the team before planning federal workloads.

How do I report a security issue?

Use the security contact published in the docs. PGP is available on request, and researchers are credited through the disclosure program.

Cite this page

Plugsky (2026). “Plugsky Security — Controls, Certifications, BYOK”. Plugsky. Available at: https://plugsky.com/articles/security (last updated 2026-09-25).