PLUG AI World Security Policy & Practices

Last updated: 28 November 2025
Applies to: plugai.world web/app/API services
CISO: ceo@plugai.world

(1) Purpose & Scope

PLUG AI WORLD is committed to protecting confidentiality, integrity, and availability across plugai.world, its APIs, Firebase-based serverless infrastructure, and AI/ML services. This policy applies to the public website, web applications, API endpoints, internal administrative systems, and operational pipelines.

(2) Governance, Roles & Responsibilities

(3) Data Classification

(4) Legal & Regulatory Compliance

We align with applicable regulations and frameworks including EU/UK GDPR, India’s Digital Personal Data Protection Act (DPDPA, 2023) and DPDP Rules, 2025, California CCPA/CPRA, and cookie/tracking requirements. We maintain transparency, lawful bases for processing, data subject rights mechanisms, breach notifications, and export control/IP compliance. Security controls are mapped to ISO/IEC 27001/27002 and SOC 2 Trust Service Criteria (readiness/alignment; certification status to be updated).

(5) Secure Architecture Overview

(6) Access Control & Identity

(7) Authentication & Session Security (User-Facing)

(8) Encryption & Key Management

(9) Application Security (Secure SDLC)

(10) Web Security Headers & Browser Protections

(11) Privacy, Data Minimization & Retention

(12) Logging, Monitoring & Alerting

(13) Infrastructure & Resilience

(14) Vulnerability Management

(15) AI/ML Security & Responsible Use

(16) Incident Response Plan (IRP)

(17) Responsible Disclosure

(18) Business Continuity & Disaster Recovery

(19) Third-Party & Sub-Processors

Note: We maintain a current list of sub-processors and DPAs. The list will be updated as services are added/removed.

(20) Secure Configuration Baselines

(21) Employee Security & Training

(22) Privacy & Cookies

(23) Policy Governance

(24) Contacts

(25) Change Log

28 Nov 2025 — Initial comprehensive publication; Firebase architecture; DPDPA references; standard RPO/RTO and remediation SLAs.