← Back to Plum It
Security
Your logins stay yours.
Plum connects your apps by holding the keys to them. Here's exactly how we keep those keys safe — in plain English.
Your Plum password
We store it one-way — scrambled so it can't be turned back into your password, not even by us. If someone stole our database, they still couldn't sign in as you.
The keys to your connected apps
When you connect an app, you hand Plum a key to it — an API token or password. Those are the crown jewels, so here's how they're guarded.
We protect your connection secrets with AWS KMS. KMS (Key Management Service) is Amazon's dedicated vault for encryption keys. The master key that locks your secrets lives inside that vault and never leaves it — not even Plum can copy it out. When one of your automations needs a secret, Plum asks the vault to unlock it for that moment, and every unlock is recorded.
Encrypted the moment you connect
Every key or token is sealed with strong encryption before it's ever written to disk.
Locked to your workspace
Each workspace's secrets are cryptographically tied to that workspace — they can't be unlocked anywhere else, even inside Plum.
Opened only when your automation runs
A secret is unlocked for a moment, in memory, by the system running your workflow — then discarded.
No reveal button, anywhere
There's no screen, support tool, or dashboard in Plum that shows a stored secret back to a person. Access is limited to the automated systems that run your workflows.
Keys rotate automatically
The master key that protects your secrets is rotated on a regular schedule.
Least access, and you're in control
We ask for only what the automation needs
The narrowest access that makes your workflow run — nothing more.
Revoke or delete anytime
Disconnect any app from your settings, or ask us to delete your data whenever you want.
The basics, covered
Encrypted in transit
Everything moves over TLS, the same encryption your bank's website uses.
Hosted on AWS
Our infrastructure runs on Amazon Web Services.
Never sold, never shared
We don't sell your data or your connected-app data, and we don't share it.
The full details live in our Privacy Policy and Terms of Service. Questions? Email support@plumit.io — or join the beta.