Security

Last Updated: July 9, 2026

This statement defines the technical and architectural safeguards deployed by Plinth to guarantee data confidentiality, integrity, and operational availability, satisfying Section 19 of POPIA.

1. Cloud Infrastructure and Physical Data Isolation

Plinth isolates its software instances within high-security, ISO 27001 and SOC 2 Type II certified data centers. The backend environments use Vercel for hosting, with database access via Supabase, restricted behind Next-Generation Web Application Firewalls (WAF) to block malicious traffic, injection attempts, and DDoS attacks.

2. Architectural Security and Access Isolation

  • Data In Transit: All information exchanged between user browsers, endpoints, and our open API nodes is protected by Transport Layer Security (TLS 1.3) protocols.
  • Data At Rest: Production databases are fully encrypted using Advanced Encryption Standard 256-bit (AES-256) at the storage volume layer. Passwords are securely hashed using strong bcrypt configurations.
  • Row-Level Security (RLS): Database interactions use strict PostgreSQL Row-Level Security (RLS) layers, ensuring each landlord can only see and access their own tenant datasets.

3. Engineering Lifecycle and Monitoring Control

The development lifecycle follows a formal Unified Agentic SDLC (u-ASDLC) methodology, running automated static code analysis and dependency vulnerability scans prior to any production updates. System performance and security parameters are monitored continuously using automated alerting tools (including Upptime and internal database logs) to detect abnormal traffic patterns instantly.

4. Incident Response and Breach Notification

In the event of a confirmed security breach, Plinth enforces a 24-hour mandatory notification protocol to the affected Subscriber and the Information Regulator, in strict compliance with Section 22 of POPIA. The incident response team conducts a full forensic investigation, documenting the root cause, impact assessment, and mitigation steps taken to prevent recurrence.

5. Contact Information for Security Inquiries

For any questions regarding our security practices or to report a potential vulnerability, please contact our security team at security@plinthcloud.com

Ready to Simplify Property Management?

Join other South African landlords who've made the switch.

No credit card required
Cancel anytime
POPIA compliant

Built for South African landlords.