Our approach to security
Pluto Suite handles sensitive financial data on behalf of Canadian freelancers and small business owners. Security is built into how the platform is designed, not added on afterward. Below is a plain-language overview of the controls in place.
Encryption in transit
All communication between your device (or browser) and Pluto Suite servers is encrypted using TLS (Transport Layer Security). This applies to the mobile app, the web app at app.plutosuite.com, and the marketing website.
Encryption at rest
- Files and receipts: all files stored in Amazon S3 (including receipt images and exported reports) are encrypted at rest using AES-256 encryption.
- Database: sensitive bank and integration tokens (the access tokens returned by Plaid after you connect an account) are additionally encrypted in our database using AES-256-GCM before storage. Even if the database were compromised, those tokens would be unreadable without the encryption key.
Account security and passwords
- Password management: authentication is handled entirely by Firebase Authentication (Google). Pluto Suite never sees, stores, or has access to your password, it is managed and hashed by Firebase using their security infrastructure.
- Two-factor authentication (2FA): two-factor authentication is supported. When enabled, a one-time code is sent to your phone number via SMS before sign-in is complete.
- Biometric lock: on supported devices, you can require Face ID or Touch ID to open the app.
- Session management: you can sign out of all active sessions at any time from your account settings.
Bank and card connections
- Handled by Plaid: bank and credit card connections are established through Plaid (US and Canada). Your online banking username and password are entered directly into those providers' secure interfaces; Pluto Suite never sees or stores your banking credentials.
- Read-only access: connections are strictly read-only. Pluto Suite can view your transaction history and balances, but cannot initiate transfers, make payments, or take any action on your accounts.
- Encrypted token storage: after connecting a bank account, we receive an encrypted access token from Plaid. That token is encrypted again with AES-256-GCM before being stored in our database.
- Disconnect any time: you can remove a linked account at any time from within the app.
Audit logging
Pluto Suite logs sensitive account actions, including: account deletion, role and permission changes, settings changes, locking the books, and export events. These logs are retained for security and compliance purposes and are not accessible to end users.
Internal access controls
Access to production systems and user data within the Pluto Suite team is governed by the principle of least privilege; team members are granted only the access their role requires, and access is reviewed regularly. Production database access is restricted and audited.
Monitoring and updates
We continuously monitor our infrastructure for unusual activity and apply security patches to dependencies and server software on a regular basis. Critical security updates are applied as quickly as possible.
Disaster recovery and backups
User data is backed up regularly on encrypted infrastructure. Backups are stored separately from the primary database and are used to recover from hardware failure or data corruption. Recovery procedures are tested periodically.
Vulnerability reporting
If you believe you've found a security vulnerability in Pluto Suite, please report it to us privately before disclosing it publicly. Send details to support@plutosuite.com with the subject line "Security Vulnerability." We will acknowledge valid reports within 3 business days and work to remediate confirmed issues as quickly as possible. We ask that you give us reasonable time to address a vulnerability before public disclosure.
Team and role-based access
For businesses with a team, Pluto Suite supports role-based permissions so each person sees only what's relevant to their role:
- Employee: log expenses and track mileage
- Accountant: full financial reports and ledger access
- Manager: review team activity and approve trips
- Owner: full billing and settings control
Questions
For any security-related questions or to report a concern, contact us at support@plutosuite.com.