SECURITY OVERVIEW ยท AUGUST 2026
Layered protection with clear boundaries.
PITCH protects contractor workspaces with tenant-scoped authorization, secure sessions, encrypted sensitive records, guarded uploads, audit evidence, and production release gates.
Application and identity
Named accounts, Argon2id password hashing, throttling, revocable sessions, CSRF protection, role/capability policies, assignment-aware workforce permissions, and server-enforced company boundaries protect application access.
Data and integrations
TLS protects connections. Dedicated authenticated-encryption keys protect connector secrets and sensitive document classes. Provider callbacks require signed verification and idempotency controls. Payment card entry remains hosted by configured payment providers.
Operations and recovery
Database-aware health checks, request-correlated redacted logs, dependency/security gates, encrypted logical backup tooling, restore verification, access-review reports, retention controls, and incident/recovery runbooks support operations. Independent backup storage, external monitoring, formal service levels, penetration tests, and certifications require separate activation or independent review.
Report a security concern
Email security@plugandplayco.com. Do not access another customer's data or disrupt service while testing.