Workspace isolation
Every operational record carries a workspace identifier, and access is enforced at the database layer with row-level security policies rather than only in application code. Membership of a workspace is required to read any of its records.
Authentication
Sign-in uses email and password with managed session handling. Sessions are validated server-side for any privileged operation. Passwords are never stored by the application.
Roles and permissions
Roles are stored separately from user profiles and evaluated by security-definer database functions, so a member cannot escalate their own privileges by editing their profile.
Evidence and documents
Credential documents are referenced from worker records and remain scoped to the owning workspace. Verification status, verifier and timestamps are retained so the proof chain stays attributable.
What we do not claim
We do not currently hold SOC 2, ISO 27001 or equivalent third-party certification, and none is implied anywhere in this product. If your procurement process requires evidence, contact us and we will share what is accurate today.
Reporting a vulnerability
Email security@plazaworkforce.app with steps to reproduce. Please do not run automated scans against the service, and give us reasonable time to remediate before any disclosure. More ways to reach us on the contact page.
