Authentication
WorkOS manages credentials. Pluto sessions are encrypted and stored in HttpOnly cookies.
Security
Pluto processes order revenue, ad spend, costs, and profit data. These are the controls implemented in the product today.
Last updated
Pluto has not completed a SOC 2 examination or ISO 27001 certification. We do not claim either standard today.
Controls
WorkOS manages credentials. Pluto sessions are encrypted and stored in HttpOnly cookies.
Shopify and Meta OAuth tokens are encrypted with AES-256-GCM before database storage.
Production database connections use TLS. Public application traffic is served over HTTPS.
Calls from the Next.js BFF to the Rust API are signed with HMAC-SHA256 and a timestamp.
Shopify, WorkOS, and Stripe webhook deliveries are verified before processing.
Backend data and queries are scoped by shop or organization. The public developer API is read-only.
Money remains decimal through ingestion, calculation, storage, and API responses.
Data handling
Pluto's primary backend, object storage, operational database, and analytics database are hosted in US regions.
Shopify order facts exclude customer names, email addresses, phone numbers, and shipping addresses.
Shopify shop-redaction events trigger deletion of the shop's facts, connections, costs, and sync history.
Technology
Interface and BFF
Backend services and object storage in the US
Business logic and integrations
AWS us-east-1, Northern Virginia
AWS us-east-1, Northern Virginia
Locks, queues, and idempotency
Authentication and organizations
Responsible disclosure
If you believe you have found a security issue, contact legal@plutoprofit.com with enough detail to reproduce it. We will review the report and respond as quickly as possible.