Security

Trust is the default.

pleom touches your most sensitive data, so security and privacy are designed in from the first line of code — not bolted on.

Encryption everywhere

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Keys are managed in a dedicated KMS with strict rotation.

Least-privilege access

Agents read only the data scopes you grant. Granular role-based access control and full audit logging come standard.

Your data stays yours

We never train shared models on your data. Each tenant is logically isolated, and you can revoke access at any time.

Compliance ready

Built to SOC 2 Type II and GDPR standards, with a Data Processing Agreement available for every customer.

Security questions or disclosures: security@pleom.co