Safety Measures
Effective date: September 1, 2026 · Last updated: September 1, 2026
Ploba takes platform safety seriously. We believe the AI ecosystem needs trusted distribution channels — not just fast ones. Every measure here exists to protect users, creators, and the integrity of the tools listed on our platform.
1. Our Approach to Safety
Ploba is a curated marketplace, not an open registry. Every tool must pass our review process before it's visible to consumers. This is a deliberate design choice: we trade listing velocity for trustworthiness.
Safety at Ploba operates across three dimensions: pre-listing review, ongoing monitoring, and incident response.
2. The Review Process
Submission Review
Every new listing and listing edit passes through our review queue before going live. Our team checks the tool's description, capabilities, and stated pricing for accuracy and compliance.
Technical Inspection
For managed and remote tools, we inspect endpoint behavior, the tool's MCP capabilities manifest, and any claimed integrations. We verify that the tool behaves as described.
Creator Verification
Creators go through a verification process that confirms their organization identity, valid support contact, and GitHub presence. Verified creators display a verification badge on their listings.
Ongoing Monitoring
After approval, we continue monitoring metering reports for anomalies, responding to user reports, and periodically re-reviewing high-volume listings.
Incident Response
If a safety issue is identified — by our team, a user report, or automated detection — we can immediately delist a tool pending investigation. Affected subscribers are notified.
3. Creator Accountability
Creators are accountable for the behavior of their tools post-approval. This includes:
- Accurate metering — creators cannot over-report usage to extract extra credits from users
- Honest changelog entries — version updates are reviewed before publication
- Security disclosures — creators must notify us immediately of any known vulnerability in their tool
- Data handling — tools must not access or exfiltrate user data beyond what is declared
Violations result in listing suspension or permanent removal and may trigger payback of any fraudulently collected revenue.
4. User Protections
Every consumer on Ploba is protected by the following guarantees:
- Your credentials and
custom_env_values(API keys you configure in a tool) are encrypted at rest - Per-app wallets isolate your credits — one compromised tool cannot drain another app's balance
- You can revoke a tool's access and delete your configuration at any time from the user settings
- All subscription changes, credit purchases, and deductions are logged in your transaction history
- Ploba holds creator payouts in a 7-day escrow window to allow for dispute resolution
5. Reporting a Safety Issue
If you believe a tool is behaving dangerously, deceptively, or maliciously, please report it immediately via our contact page with the subject line "Safety Report". We aim to acknowledge safety reports within 24 hours.
For security vulnerabilities in Ploba itself (not a specific tool), see our responsible disclosure process.
6. AI-Specific Considerations
We recognize that AI tools carry unique risks — unpredictable outputs, prompt injection vulnerabilities, and potential for misuse. Our review process specifically looks for:
- Prompt injection attack surfaces in tools that accept user input
- Tools that could be repurposed for automated harassment or spam
- Misleading capability claims (e.g., claiming HIPAA compliance without evidence)
- Tools with access to sensitive scopes (filesystem, network, code execution) that lack adequate disclosure
We continue to evolve our review criteria as the AI landscape matures. See our Trust Center for our broader platform trust posture.
7. Third-Party Tools — Limits of Our Responsibility
Some tools listed on Ploba are created and operated by independent third-party creators. Others are sourced from public repositories and the broader open-source AI ecosystem. In all cases, Ploba acts as a distribution platform only — we are not the developer or operator of these tools and cannot control their underlying logic, model behaviour, training data, or outputs.
Third-party tools are provided for informational and productivity purposes only. Outputs generated by AI tools do not constitute professional advice. Users are solely responsible for verifying any output before acting on it. Ploba accepts no liability for damages arising from reliance on third-party tool outputs.
For full details, see our Third-Party Tools Disclaimer.