LegalSecurity
Security at Plurel
Last updated
The short version
Plurel is building a way for groups to pay together, so trust is the product. We build on modern web security practices, keep access to our systems tight, and test our own work for weaknesses before anyone else can.
We also know the threats are changing. AI agents and automated attacks are getting more capable, and we work to stay ahead of them. Found a problem? Write to contact@plurelinc.com.
01How we build
The website follows current best practices for the modern web:
- Encrypted everywhere. Every page is served over HTTPS, and browsers are told never to connect to us any other way (HSTS, on the browser preload list).
- Hardened browsers. Strict security headers stop our pages being framed by other sites, limit what a page can access (no camera, microphone or location), and keep browsers from guessing file types.
- A protected network. We run on Cloudflare’s global network, which absorbs attacks and abusive traffic before it reaches us.
- No secrets in code. Keys and credentials live in a dedicated secrets store, never in our source code, and each one is used only by the system that needs it.
02AI agents and AI risk
AI is changing what attackers can do. Automated agents can probe websites, fill in forms and try to trick other AI systems into following hidden instructions. We take that seriously and design for it:
- Bots are checked. Our sign-up forms use Cloudflare Turnstile, which tells people from automated traffic without making you solve puzzles.
- AI treats content as data, not orders. Where we use AI, it’s told to treat what it reads as information, never as instructions, which guards against prompt injection.
- We keep watching. We follow new AI attack techniques as they appear and update our defenses as they change.
03Testing and monitoring
We look for weaknesses before anyone else can:
- Deep vulnerability scans. We regularly scan our code, its dependencies and our live systems for known vulnerabilities and fix what we find.
- Security review of every change. Changes are reviewed for security issues before they ship, with AI-assisted review alongside our own.
- Monitoring. We track errors and unusual behavior in production so we can spot and fix problems quickly.
04Your information
- Limited access. Access to systems and data is limited to the people who need it, protected by strong sign-in checks.
- Data we don’t keep. We collect as little as we can. When a provider holds a temporary copy of something for us, we delete it once we no longer need it there.
05Who we work with
The website relies on a small number of established providers, each under contract:
- Cloudflare: hosting, network protection and bot checks.
- Loops: the newsletter list and its emails.
- PostHog: website analytics and error monitoring.
What each one receives is in our privacy policy.
06The Plurel app
The Plurel app isn’t live yet. Before it launches, we’ll expand this page to cover how the app protects your account, your payments and your card, and who we work with to do it. Newsletter subscribers will hear when it’s updated.
07Report a security problem
If you think you’ve found a vulnerability in Plurel, please tell us at contact@plurelinc.com. Include what you found, how to reproduce it and anything that helps us understand the impact. We’ll reply as soon as we can and keep you posted while we fix it.
Please act in good faith: don’t access or change other people’s data, don’t disrupt our service, and give us a reasonable chance to fix the problem before you share it. If you do, we won’t take action against you for your research.