Safety Practices

A transparent overview of our security practices, from how we store passwords to how we isolate per-app wallets — and how to report a vulnerability if you find one.

How we protect you

Security practices

Authentication & sessions

  • JWT access tokens (15-min expiry) + refresh tokens (7-day) in HttpOnly cookies
  • Email OTP multi-factor authentication available on all accounts
  • Per-device session tracking with one-click remote revocation
  • CSRF token enforcement on all state-mutating endpoints
  • Rate limiting and brute-force protection via Arcjet

Data protection

  • All data encrypted in transit via TLS 1.2+
  • Passwords hashed with Argon2id before storage — never reversible
  • User API keys (custom_env_values) encrypted at rest with AES-256
  • Per-app credit wallets are isolated — one tool cannot drain another
  • Full audit log trail for all sensitive account and billing actions

Infrastructure

  • Serverless infrastructure — no persistent attack surface
  • Database access restricted to the application layer
  • Dependencies reviewed and updated on a rolling basis
  • Secrets managed via environment variables, never in source control

Monitoring & response

  • Real-time anomaly detection on metering and billing patterns
  • Structured logging with audit trails for all admin operations
  • Incident response process with defined severity SLAs
  • Post-incident reviews published publicly when appropriate

Responsible disclosure

If you discover a vulnerability in Ploba, please report it privately before any public disclosure. We follow coordinated disclosure and commit to:

  • Acknowledge your report within 48 hours
  • Provide regular status updates as we investigate
  • Fix confirmed issues within a reasonable timeframe
  • Credit your contribution (if you wish)
  • Not take legal action against good-faith researchers
Report a vulnerability

In scope

  • Authentication bypass or session hijacking
  • SQL injection or data exfiltration
  • CSRF attacks on protected endpoints
  • Privilege escalation (accessing another user's data or wallet)
  • XSS vulnerabilities in the storefront or console
  • Sensitive data exposure in API responses

Out of scope

  • Denial-of-service attacks
  • Social engineering of Ploba staff
  • Vulnerabilities in third-party tools listed on the marketplace
  • Issues already disclosed or under remediation