Security
Built to protect a stock list, not just store it.
In this trade an inventory is commercially sensitive and a physical security matter. plenty100 keeps yours isolated, controlled and recoverable, and tells you plainly what is still being built.
Hosted on Google Cloud · Isolated per business · Every action logged
Isolated per business
Every customer's data lives in its own tree, and the database itself refuses any request from a user who does not belong to that business.
Controlled by role
Access is granted module by module and branch by branch. Cost prices, source and deletions sit behind an admin password.
Logged end to end
Sign-ins, page views, changes and deletions are recorded against the person who made them. An item's history stays with it for life.
Certified foundations
Runs on Google Cloud, whose Firebase services hold ISO 27001 and SOC 1, 2 and 3 reports. Encrypted in transit and at rest.
Isolation
One business, one tree, one rule
plenty100 is one platform serving many businesses, so the first question is how yours is kept apart from everyone else's. Each business is a separate branch of the database, and every request carries the signed-in user's workspace. If the workspace on the request does not match the data being asked for, the database refuses it before the app sees a single record.
- Enforced in the database rules, not only in the app, so a bug or a tampered client cannot reach into another business
- Photos, documents and signed appro PDFs are stored behind the same per-business boundary
- An automated check fails our build if any query is not tied to a workspace
- Within your business, branch access is set per user, so a branch sees its own stock and the group view belongs to those you choose
Activity log today
Where your data lives
Certified infrastructure, in your region
Everything beneath the application, from the data centres to the operating systems, is run by Google Cloud. Everything above it is ours.
Access control
Who sees what is your decision
Permissions are set per user, per module and per branch, and the actions that matter most ask for more than a login.
Per user, per module
Each person is given only the parts of the platform they need: inventory, appro, invoicing, clients, reporting or admin, switched on one module at a time.
Per branch
A branch works its own stock and its own appros. The group view, and the right to move stock between branches, belong to the people you choose.
Password-protected actions
Changing a cost or source price, deleting a client or permanently removing an item asks for your business's admin password. It is stored only as a hash, and you can change it whenever you like.
Recycle first, delete second
Deleted items go to a recycle area where an admin can restore them. Permanent deletion is a separate, password-protected step, so a slip of the finger is not a loss.
Sessions that end
Browser sessions sign out after two hours without activity. Removing a user revokes their sign-in, and can disable the account in the same step.
Phones kept current
The iPhone and Android apps refuse to run below a minimum version we set, so a security fix reaches every device rather than waiting for someone to update.
Have a security questionnaire to complete?
Send it over. We answer vendor questionnaires in plain language, and we say so where an answer is "not yet".
Audit trail
Every change has a name next to it
The question after a discrepancy is always who, when and from where. The platform answers it from its own records, without a forensic exercise.
Item history
Every material change to an item, from price to location to status, is written to its record with the user and the time, and stays for the life of the item.
Activity tracker
Sign-ins, page views, button presses and every create, update and delete are logged per user and kept for six months.
Application logs
Errors and system events are kept for thirty days and can be read by your admin from inside the platform, so a problem is traced rather than guessed at.
Your data
Yours to keep, yours to take away
We are custodians of your inventory, not owners of it. The platform is built so that leaving is as straightforward as joining.
Export at any time
Any view exports to Excel for your accountant, your auditor or your own records, whenever you like and without asking us.
Leaving
If a subscription or a trial ends, we export your data back to you and remove your workspace. Nothing is kept for leverage.
Data protection law
We act as the processor of your data under South Africa's POPIA and the UK GDPR. A data processing agreement is available on request.
AI, on your terms
The assistant is given only the records needed to answer. Our AI provider does not use what we send to train its models, and nothing goes to a client until a person approves it.
Who we rely on
Four companies touch your data on our behalf, each for one job.
- Google Cloud (Firebase): hosting, database, sign-in and file storage.
- OpenAI: the AI features, under terms that exclude training on what we send.
- Meta (WhatsApp Business Platform): the WhatsApp messages you send and receive in the platform.
- Cloudflare: the bot check on this website's forms and the website's cookie-free visitor analytics. Nothing inside the platform.
How we build and run it
Few hands on production, all of them named
plenty100 is run by a small team. That means fewer people with access, no shared logins, and nobody hiding behind a ticket queue when you have a question.
Rules ship with the code
The database and storage rules live in the codebase and are deployed with every release, so the protection and the product never drift apart. Every library is locked to a known version and updated deliberately.
Secrets kept out of the app
Keys for integrations such as WhatsApp and the AI provider are held in Google Secret Manager and reach only the server-side functions that need them. None are shipped inside the apps.
Least privilege, for us too
Administrative access to production is held by a small number of named people and used for support and operations, never for anything else. People are removed the day they leave.
Where we are heading
Honest about what is done and what is next
Security questionnaires ask for certificates. Here is where we stand on them, without dressing it up. If your business needs a particular control before a date below, ask: several are a configuration away rather than a year away.
- Now: hardeningDaily independent backups with a tested restore, device attestation for the phone apps, and written runbooks for access removal and recovery. In progress through the end of 2026.
- 2027: governance and independent testingWritten security policies, a risk register, an independent penetration test and a data processing agreement as standard, with a compliance platform collecting the evidence continuously.
- 2027 to 2028: SOC 2 and ISO 27001A SOC 2 Type I report first, then the Type II observation period. ISO 27001 follows for customers who require it, and Cyber Essentials for the United Kingdom.
Questions we are asked
Can plenty100 staff see our stock?
A small number of named people at plenty100 hold administrative access for support and operations. It is used when you ask us for help or to keep the service running, and your stock and client data are never used for anything else.
Where is our data stored?
In Google Cloud's Johannesburg region, replicated across several zones there, and encrypted in transit and at rest. A London database is planned for customers in the United Kingdom.
Can one branch see another branch's stock?
Only if you set it up that way. Access is granted per user and per branch, so a branch works its own stock and the group view belongs to the people you choose.
Do you use our data to train AI?
No. The assistant is given only the records needed to answer a question, our AI provider does not use what we send to train its models, and nothing is sent to a client until a person approves it.
What happens to our data if we leave?
You can export everything yourself at any time. When a subscription or trial ends, we export your data back to you and remove your workspace.
Do you hold SOC 2 or ISO 27001?
Not yet. The Google Cloud infrastructure the platform runs on does, and our own programme is under way: a SOC 2 report is the next milestone, with ISO 27001 following for customers who require it. In the meantime we answer security questionnaires in full.
How do we report a security concern?
Email info@plenty100.com with Security in the subject line. A person reads it, and you will hear back within one business day.
Still have a question about security?
Ask it. You will get a straight answer from the people who build the platform, and if something is not in place yet, we will tell you when it will be.