Exhibit B
Security Measures
1. Security Program Overview
Plumloom maintains a security program designed to protect the confidentiality, integrity, and availability of Customer Data, including data submitted by individual users. Security measures are implemented based on the nature of the Services, the sensitivity of data processed, and prevailing industry practices for early-stage SaaS platforms.
These measures apply equally to business and individual users of the Services and are intended to satisfy the requirement for "reasonable technical and organizational measures" under Applicable Data Protection Laws.
2. Access Controls
- Access to production systems is restricted to authorized personnel on a least-privilege basis.
- Administrative access is protected by strong authentication mechanisms.
- Employee access rights are reviewed periodically and promptly revoked upon role change or termination.
- Customer access to the Services is authenticated using account-based credentials.
3. Data Protection & Encryption
- Customer Data, including data submitted by individual users is transmitted over encrypted channels using industry-standard transport encryption (e.g., TLS).
- Customer Data, including data submitted by individual users stored in production systems is protected using logical access controls.
- Secrets, credentials, and access tokens are stored using secure configuration and secret-management practices.
- Plumloom implements logical isolation mechanisms to segregate customer workspaces, prompts, and evaluation data. Access to model integrations is controlled at the account or workspace level. Customer is responsible for ensuring that prompts, inputs, and configurations do not contain sensitive or regulated data unless expressly permitted under the Agreement.
- Plumloom does not intentionally store plaintext credentials.
4. Infrastructure & Availability
- The Services are hosted on reputable third-party cloud infrastructure providers.
- Logical separation is maintained between production and non-production environments.
- Reasonable measures are taken to protect against unauthorized access, data loss, and service disruption, including backups and infrastructure redundancy appropriate to the Service tier.
5. Secure Development Practices
- Plumloom follows secure development practices appropriate to its stage, including code review and change management.
- Dependencies and third-party libraries are monitored for known security issues where practicable.
- New features and changes are tested prior to deployment to production.
- Where required by law, Plumloom will also provide notice to affected individual users.
6. Incident Response & Breach Management
- Plumloom maintains procedures to identify, investigate, and respond to security incidents.
- Upon confirmation of a Security Incident affecting Customer Data, including data submitted by individual users, Plumloom will notify Customer without undue delay and within a reasonable time, as described in the DPA.
- Plumloom will take reasonable steps to contain, mitigate, and remediate confirmed incidents.
7. Vendor & Subprocessor Security
- Plumloom engages subprocessors subject to contractual obligations consistent with applicable data-protection requirements.
- Subprocessors are selected based on security, reliability, and service suitability.
- Plumloom remains responsible for subprocessors' processing of Customer Data, including data submitted by individual users as set forth in the DPA.
8. Monitoring & Logging
- System activity is logged to support operational monitoring, troubleshooting, and security review.
- Logs are protected against unauthorized access and retained for a limited period consistent with operational needs.
9. Updates to Security Measures
Plumloom may update or enhance these Security Measures from time to time.
Any updates will not materially reduce the overall level of security provided for the Services during the applicable term.
Plumloom may pursue third-party security attestations or certifications (including SOC 2 or ISO standards) in the future. No representation or warranty is made that any such certification has been achieved unless expressly stated in writing.