Security

How the platform is secured

A plain description of the controls that exist in the product today. We do not claim certifications we have not obtained.

Workspace isolation

Every operational record carries a workspace identifier, and access is enforced at the database layer with row-level security policies rather than only in application code. Membership of a workspace is required to read any of its records.

Authentication

Sign-in uses email and password with managed session handling. Sessions are validated server-side for any privileged operation. Passwords are never stored by the application.

Roles and permissions

Roles are stored separately from user profiles and evaluated by security-definer database functions, so a member cannot escalate their own privileges by editing their profile.

Evidence and documents

Credential documents are referenced from worker records and remain scoped to the owning workspace. Verification status, verifier and timestamps are retained so the proof chain stays attributable.

What we do not claim

We do not currently hold SOC 2, ISO 27001 or equivalent third-party certification, and none is implied anywhere in this product. If your procurement process requires evidence, contact us and we will share what is accurate today.

Reporting a vulnerability

Email security@plazaworkforce.app with steps to reproduce. Please do not run automated scans against the service, and give us reasonable time to remediate before any disclosure. More ways to reach us on the contact page.