Plaw+1 (628) 296-7377

Security

This page covers two things: the security of this website, and how Plaw handles customer data during an engagement. If you have found a vulnerability, email security@plaw.io. We acknowledge every report within 3 business days.

This website

plaw.io is a static site with zero client JavaScript. There are no user accounts, no login, and no payment processing here. Nothing you type is stored on this site, because there is nowhere to type it. Pages are served by Cloudflare Pages over HTTPS.

That keeps the attack surface small on purpose. A page of HTML cannot leak a session it never created.

Reporting a vulnerability

We publish a security.txt at /.well-known/security.txt. Send reports to security@plaw.io, or to yaz@plaw.io if you want a named person. We acknowledge reports within 3 business days and tell you what we plan to do about the finding. English preferred. There is no bug bounty, but real findings get fixed promptly and credited if you want credit.

Customer data in operations

The website is the small part. Plaw runs agents inside customer businesses, and that work touches operational data: inspection schedules, deficiency records, customer and job information. That data is handled under the engagement agreement each customer signs, which states what we access, what we store, and for how long.

Agent actions are bounded by Veto, Plaw's open-source authorization layer. Veto decides what an agent is allowed to do before it does it, not after. Consequential actions, meaning anything that moves money, commits the business, or reaches a customer, wait for a person to approve them.

Plaw holds no compliance certifications today. No SOC 2, no ISO 27001. We would rather say that plainly than imply otherwise. If your procurement process needs a specific attestation, ask, and we will tell you exactly where we stand.