PlutoVault — CID DCIM

At PlutoVault, maintaining the highest standards of security and privacy comes first. We protect your data across an isolated, continuously-monitored infrastructure and give you the reports and controls to verify it. Operated by Redline Analytics LLC.

Compliance

SOC 2 Type II
Observation period underway
Live control monitoring
31/32 automated checks passing
Penetration test
Independent, annual
GDPR aligned
DSAR + 30-day deletion

Resources View all

Compliance

Controls Updated Jun 18, 2026 View all

Security (Common Criteria)
CC1.1Control environment (policies established & acknowledged)
CC2.1Communication of objectives (policies + privacy notice published)
CC3.1Risk assessment (risk register maintained)
View 13 more Security (Common Criteria) controls
Availability
A1.2Automated nightly encrypted backups
A1.4Disaster-recovery failover tested
A1.5Disaster-recovery replication (live, cross-region)
View 2 more Availability controls
Confidentiality
C1.1Data classification policy
C1.2Data retention + DSAR deletion procedure
Processing Integrity
PI1.1Input validation (Pydantic + Form validation at all boundaries)
PI1.2Billing transaction log (BillingEvent table)
Privacy
P1.1Privacy policy published at /privacy
P4.1Data use limitation (personal info used only as communicated)
P6.1Data retention limits (personal info retained per stated policy)
View 4 more Privacy controls

How we protect your data

Encryption

Credentials encrypted at rest with authenticated AES encryption and per-tenant keys; TLS 1.2+ in transit. BYOK with your own cloud KMS available.

Access Control

Enterprise SSO (SAML/OIDC) with MFA enforced; role-based access; per-tenant isolation; quarterly access reviews.

Backups & DR

Nightly encrypted backups with point-in-time recovery; active-passive cross-cloud DR for the portal.

Monitoring

Continuous observability with alerting; weekly automated vulnerability scanning of all systems.

Incident Response

Formal 6-phase incident response with automated detection, containment, and post-mortems.

Tenant Isolation

Every customer runs in a dedicated, isolated environment with its own database and encryption key.

Bring Your Own Key

Customers can own the encryption key that protects their credentials. Each secret is wrapped by a master key in your AWS, Google Cloud, or Azure KMS using envelope encryption — PlutoVault never holds your plaintext master key. Revoke your key and your data becomes permanently unreadable.

Request the BYOK setup guide →

PlutoVault is operated by Redline Analytics LLC · Security contact: security@redlineanalytics.net · Home · Privacy · Terms

Request access

Already have access? Reclaim access

Resources
Access level