plenty100

Security

Built to protect a stock list, not just store it.

In this trade an inventory is commercially sensitive and a physical security matter. plenty100 keeps yours isolated, controlled and recoverable, and tells you plainly what is still being built.

Hosted on Google Cloud · Isolated per business · Every action logged

Isolated per business

Every customer's data lives in its own tree, and the database itself refuses any request from a user who does not belong to that business.

Controlled by role

Access is granted module by module and branch by branch. Cost prices, source and deletions sit behind an admin password.

Logged end to end

Sign-ins, page views, changes and deletions are recorded against the person who made them. An item's history stays with it for life.

Certified foundations

Runs on Google Cloud, whose Firebase services hold ISO 27001 and SOC 1, 2 and 3 reports. Encrypted in transit and at rest.

Isolation

One business, one tree, one rule

plenty100 is one platform serving many businesses, so the first question is how yours is kept apart from everyone else's. Each business is a separate branch of the database, and every request carries the signed-in user's workspace. If the workspace on the request does not match the data being asked for, the database refuses it before the app sees a single record.

  • Enforced in the database rules, not only in the app, so a bug or a tampered client cannot reach into another business
  • Photos, documents and signed appro PDFs are stored behind the same per-business boundary
  • An automated check fails our build if any query is not tied to a workspace
  • Within your business, branch access is set per user, so a branch sees its own stock and the group view belongs to those you choose
Checked before any data movesEvery request is tested against the signed-in user's workspace by the database itself, whatever the app asks for.

Where your data lives

Certified infrastructure, in your region

Everything beneath the application, from the data centres to the operating systems, is run by Google Cloud. Everything above it is ours.

Johannesburg
Your records are held in Google Cloud's Johannesburg region and replicated across several zones there. A London database is planned for customers in the United Kingdom.
Encrypted
In transit, with HTTPS on every connection. At rest in the database, in file storage and in the sign-in service. Passwords are never stored in a readable form.
ISO 27001
With SOC 1, SOC 2 and SOC 3: the reports Google holds for every Firebase service the platform runs on, renewed on their audit cycle, not ours.

Access control

Who sees what is your decision

Permissions are set per user, per module and per branch, and the actions that matter most ask for more than a login.

Per user, per module

Each person is given only the parts of the platform they need: inventory, appro, invoicing, clients, reporting or admin, switched on one module at a time.

Per branch

A branch works its own stock and its own appros. The group view, and the right to move stock between branches, belong to the people you choose.

Password-protected actions

Changing a cost or source price, deleting a client or permanently removing an item asks for your business's admin password. It is stored only as a hash, and you can change it whenever you like.

Recycle first, delete second

Deleted items go to a recycle area where an admin can restore them. Permanent deletion is a separate, password-protected step, so a slip of the finger is not a loss.

Sessions that end

Browser sessions sign out after two hours without activity. Removing a user revokes their sign-in, and can disable the account in the same step.

Phones kept current

The iPhone and Android apps refuse to run below a minimum version we set, so a security fix reaches every device rather than waiting for someone to update.

Plenty control, 100% of your businesses.

Have a security questionnaire to complete?

Send it over. We answer vendor questionnaires in plain language, and we say so where an answer is "not yet".

Audit trail

Every change has a name next to it

The question after a discrepancy is always who, when and from where. The platform answers it from its own records, without a forensic exercise.

Item history

Every material change to an item, from price to location to status, is written to its record with the user and the time, and stays for the life of the item.

Activity tracker

Sign-ins, page views, button presses and every create, update and delete are logged per user and kept for six months.

Application logs

Errors and system events are kept for thirty days and can be read by your admin from inside the platform, so a problem is traced rather than guessed at.

Your data

Yours to keep, yours to take away

We are custodians of your inventory, not owners of it. The platform is built so that leaving is as straightforward as joining.

Export at any time

Any view exports to Excel for your accountant, your auditor or your own records, whenever you like and without asking us.

Leaving

If a subscription or a trial ends, we export your data back to you and remove your workspace. Nothing is kept for leverage.

Data protection law

We act as the processor of your data under South Africa's POPIA and the UK GDPR. A data processing agreement is available on request.

AI, on your terms

The assistant is given only the records needed to answer. Our AI provider does not use what we send to train its models, and nothing goes to a client until a person approves it.

Who we rely on

Four companies touch your data on our behalf, each for one job.

  • Google Cloud (Firebase): hosting, database, sign-in and file storage.
  • OpenAI: the AI features, under terms that exclude training on what we send.
  • Meta (WhatsApp Business Platform): the WhatsApp messages you send and receive in the platform.
  • Cloudflare: the bot check on this website's forms and the website's cookie-free visitor analytics. Nothing inside the platform.

How we build and run it

Few hands on production, all of them named

plenty100 is run by a small team. That means fewer people with access, no shared logins, and nobody hiding behind a ticket queue when you have a question.

Rules ship with the code

The database and storage rules live in the codebase and are deployed with every release, so the protection and the product never drift apart. Every library is locked to a known version and updated deliberately.

Secrets kept out of the app

Keys for integrations such as WhatsApp and the AI provider are held in Google Secret Manager and reach only the server-side functions that need them. None are shipped inside the apps.

Least privilege, for us too

Administrative access to production is held by a small number of named people and used for support and operations, never for anything else. People are removed the day they leave.

Where we are heading

Honest about what is done and what is next

Security questionnaires ask for certificates. Here is where we stand on them, without dressing it up. If your business needs a particular control before a date below, ask: several are a configuration away rather than a year away.

  1. Now: hardeningDaily independent backups with a tested restore, device attestation for the phone apps, and written runbooks for access removal and recovery. In progress through the end of 2026.
  2. 2027: governance and independent testingWritten security policies, a risk register, an independent penetration test and a data processing agreement as standard, with a compliance platform collecting the evidence continuously.
  3. 2027 to 2028: SOC 2 and ISO 27001A SOC 2 Type I report first, then the Type II observation period. ISO 27001 follows for customers who require it, and Cyber Essentials for the United Kingdom.

Questions we are asked

Can plenty100 staff see our stock?

A small number of named people at plenty100 hold administrative access for support and operations. It is used when you ask us for help or to keep the service running, and your stock and client data are never used for anything else.

Where is our data stored?

In Google Cloud's Johannesburg region, replicated across several zones there, and encrypted in transit and at rest. A London database is planned for customers in the United Kingdom.

Can one branch see another branch's stock?

Only if you set it up that way. Access is granted per user and per branch, so a branch works its own stock and the group view belongs to the people you choose.

Do you use our data to train AI?

No. The assistant is given only the records needed to answer a question, our AI provider does not use what we send to train its models, and nothing is sent to a client until a person approves it.

What happens to our data if we leave?

You can export everything yourself at any time. When a subscription or trial ends, we export your data back to you and remove your workspace.

Do you hold SOC 2 or ISO 27001?

Not yet. The Google Cloud infrastructure the platform runs on does, and our own programme is under way: a SOC 2 report is the next milestone, with ISO 27001 following for customers who require it. In the meantime we answer security questionnaires in full.

How do we report a security concern?

Email info@plenty100.com with Security in the subject line. A person reads it, and you will hear back within one business day.

100% of your businesses, Plenty control.

Still have a question about security?

Ask it. You will get a straight answer from the people who build the platform, and if something is not in place yet, we will tell you when it will be.