Plondo
Locating weather…

Security

Security at Plondo

Plondo Network, Inc takes security seriously across access, data protection, resilience, and monitoring for its direct selling platform. Plondo requires strong authentication and role based permissions, protects data in transit and at rest, and maintains tested backups and a documented incident response plan. Plondo is PCI DSS compliant, applies SOC 2 Type 2 aligned controls to client engagements, and handles personal data in line with GDPR and CCPA. Control documentation is available to qualified prospects on request.

Compliance and data protection

Plondo Network, Inc is PCI DSS compliant. Our Attestation of Compliance is available to qualified prospects on request. Card payments are processed through PCI DSS compliant providers, and Plondo does not store raw card numbers.

Plondo has designed and operated SOC 2 Type 2 compliant environments for client engagements, and applies that same control framework to the systems it builds and runs.

Plondo handles personal data in line with GDPR and CCPA, including data subject access and deletion requests.

What Plondo provides

  • PCI DSS compliant payment handling, with no raw card numbers stored on Plondo systems.
  • SOC 2 Type 2 aligned controls across access, change management, logging, and monitoring.
  • Attestation and control documentation available on request under a non disclosure agreement.

Shared responsibility model

Plondo operates the direct selling platform itself: the application, the database behind it, and the servers it runs on. The company that uses Plondo configures its own side of the relationship, including who on its team gets access and what role each person holds.

No platform is secure on its own. Plondo's program and a customer's own configuration choices both matter, and a gap on either side can undermine the other.

A simplified view of who is responsible for what
AreaPlondo's sideYour side
Platform and infrastructureBuilds, hosts, and maintains the application, the database, and the servers it runs on.Nothing to configure. This sits entirely with Plondo.
Accounts and rolesProvides the login, role, and permission controls inside the platform.Decides which staff get an account and which role each person holds.
Devices and networksNot in scope for Plondo.Securing the computers, phones, and networks your team uses to reach Plondo.
Data entered into the platformStores and processes what is entered.Decides what customer, distributor, and order data your team enters or connects.

What Plondo provides

  • A written summary of what Plondo operates versus what your team configures.
  • Account and role controls that your own team administers once Plondo issues access.
  • Notice when a new feature shifts where a control lives between Plondo and your team.

Authentication and access

Plondo's platform enforces login controls built around role based access and least privilege. Multi factor authentication can be required for every user, and single sign on works with common identity providers so your team can enforce its own authentication standard. Session controls limit how long a login stays active, and access is removed promptly when an employee leaves your team.

What Plondo provides

  • Multi factor authentication that can be required for every user, not only offered as an option.
  • Role based permissions scoped to the data and actions each person actually needs.
  • Single sign on support with common identity providers.
  • Prompt removal of a departing employee's access once your team requests it.

Data protection

Plondo protects data in transit with modern TLS encryption and protects stored data with encryption at rest. Secrets and encryption keys are held in managed secret and key storage rather than in application code.

Payment data is handled by PCI DSS compliant processors, and Plondo does not store raw card numbers on its own systems. If your company stops using Plondo, your data can be exported and returned.

What Plondo provides

  • Encryption in transit using modern TLS between a user's browser and Plondo's servers.
  • Encryption at rest for stored customer, distributor, and order data.
  • Managed secret and key storage rather than keys embedded in application code.
  • Payment handling through PCI DSS compliant processors, with no raw card numbers stored on Plondo systems.
  • Data export and return if your company stops using Plondo.

Tenancy and isolation

Plondo serves many direct selling companies from a shared platform, and keeps each company's data logically isolated inside it. Environments are separated, and access to a company's data is scoped to that company, so staff and processes reach only the data their role covers.

What Plondo provides

  • Logical isolation of your company's data from every other company on the platform.
  • Separated environments and access scoped per company.
  • A clear path to export your data, with isolation preserved, if you leave the platform.

Secure development

Plondo reviews every code change through peer review before it reaches the live platform. Automated tools scan dependencies and code for known vulnerabilities on an ongoing basis. Plondo always maintains separate development and staging environments, and every change moves through them before it reaches production.

Plondo also commissions periodic third party penetration testing and tracks findings through to remediation.

What Plondo provides

  • Peer code review before any change reaches the live platform.
  • Automated dependency and vulnerability scanning.
  • Separate development, staging, and production environments that every change passes through.
  • Periodic third party penetration testing, with findings tracked to remediation.

Logging and audit trails

Plondo keeps audit logs of account and administrative actions across the platform. Logs are centralized and monitored with alerting, and your own admins can view and export the activity that belongs to your company.

What Plondo provides

  • Audit logs of account and administrative actions.
  • Centralized logging with alerting on the activity that matters.
  • Admin visible and exportable activity logs for your company.

Backups and business continuity

Plondo runs automated backups daily, and as frequently as every five minutes for clients that require it. Backups are tested by actually restoring from them, not only taking them, and are retained from three to seven years depending on the client's requirements. A business continuity plan sets recovery time and recovery point objectives for the platform, shared with prospects during procurement.

What Plondo provides

  • Automated daily backups, with intervals as frequent as every five minutes for clients that require it.
  • Backup retention from three to seven years, set by the client's requirement.
  • Backups tested through real restores, not only taken.
  • A business continuity plan with recovery time and recovery point objectives, shared during procurement.

Incident response

Plondo maintains a documented incident response plan covering detection, alerting, containment, and customer notification. The team runs practice exercises so the plan holds up when it matters.

What Plondo provides

  • A documented incident response plan covering detection, containment, and notification.
  • Detection and alerting built into the platform.
  • A customer notification process once an incident involving your data is confirmed.
  • Practice exercises that test the incident response plan.

Subprocessors and vendor risk

Plondo vets the outside infrastructure and service providers it relies on to run parts of its platform. A current subprocessor list is available on request, new providers are reviewed before onboarding, and your company is notified of changes that affect your data.

What Plondo provides

  • A current list of vetted subprocessors, available on request.
  • Review of a new provider before it is onboarded.
  • Notice when a subprocessor change affects your data.

Privacy and personal data requests

Plondo handles personal data with data minimization and defined retention limits. Plondo honors data subject access, correction, and deletion requests, verifies the identity of the person making a request, and routes requests from your own distributors or customers appropriately.

The privacy policy describes what personal data Plondo collects and how it is used.

What Plondo provides

  • Data minimization and retention limits on personal data.
  • Data subject access, correction, and deletion, with identity verification.
  • Routing for privacy requests that come from your distributors or customers.

Responsible disclosure

Plondo welcomes responsible disclosure of a security weakness through the contact page rather than a public post. Use the contact page to reach Plondo's team, describe what you found, and include enough detail for Plondo to reproduce it.

Plondo reads every report that comes in through that channel, acknowledges it, and follows up directly with the person who submitted it.

What Plondo provides

  • Acknowledgement of a submitted report through the contact page.
  • Follow up directly with the person who reported it.
Contact Plondo

Opens the Plondo contact page.

Learn more

This page describes the security measures Plondo applies and the compliance posture it maintains for the direct selling platform.

For Plondo's privacy commitments, read the privacy policy. For a security report or any other question, use the contact page. For more about the company behind Plondo, see the about page.