Data Security Overview
Our Security Practices and Data Protection Standards
Protecting client data is not something we take lightly. PlotPath handles financial records, operational data, and personal information for businesses that depend on accuracy and confidentiality. Because of that responsibility, our internal systems follow a strict security baseline that prioritizes identity protection, threat detection, data governance, and device security.
All measures listed on this page are actively in place and operated as part of an ongoing security lifecycle. They are maintained, monitored, and reviewed regularly to ensure they remain aligned with best practices. Our approach follows a Zero Trust mindset: verify every access attempt, use least privilege, and protect data above all else.
Security Controls Implemented
| Security Area | Control Implemented | Purpose |
|---|---|---|
| Identity and Access Security | Mandatory strong passwords (12+ characters, no reuse) | Reduces risk of brute-force and credential-stuffing attacks. |
| Identity and Access Security | Enforced 2-Step Verification (MFA) for all users and admins | Blocks the majority of account takeover attempts. |
| Identity and Access Security | Blocked installation of non-allowlisted third-party apps | Eliminates unvetted apps that could exfiltrate data or introduce malware. |
| Identity and Access Security | Real-time critical admin alerts for high-risk actions | Enables immediate investigation of privilege changes or suspicious activity. |
| Identity and Access Security | Context-aware access policies restrict system login to authorized geographic regions (currently the United States and Uruguay). Team members traveling outside those regions are temporarily added to a managed access group for the duration of their travel. | Ensures that client data cannot be accessed from unauthorized locations, even with valid credentials. |
| Advanced Email and Threat Protection | Enhanced malware and phishing protection | Filters known and emerging threats before they reach any inbox. |
| Advanced Email and Threat Protection | Security sandbox for email attachments | Executes attachments in isolation to stop zero-day attacks. |
| Advanced Email and Threat Protection | OCR scanning for image-based phishing attempts | Detects malicious links embedded inside images. |
| Data Governance and Compliance | Retention policies in Google Vault for required record preservation | Supports compliance, eDiscovery, and legal protection. |
| Data Governance and Compliance | Data labeling framework (Public, Internal, Client-Confidential, PII-Sensitive) | Classifies and manages sensitive data throughout the organization. |
| Data Governance and Compliance | Data Loss Prevention rules for confidential and sensitive information | Prevents accidental or intentional external sharing of protected data. |
| Data Governance and Compliance | Drive Trust Rules for controlled external sharing | Warns or blocks users when attempting to share data externally. |
| Data Governance and Compliance | Data region locked to the United States | Keeps covered data stored within US boundaries. |
| Spam and Phishing Mitigation | Custom blocked-sender rules | Reduces inbound spam and known malicious sources. |
| Spam and Phishing Mitigation | Safety rules for lookalike domains and new external senders | Adds friction before users respond to high-risk messages. |
| Endpoint and Device Security | Advanced Mobile Device Management for iOS and Android | Enforces passcodes, encryption, and remote-wipe capability. |
| Endpoint and Device Security | Migrate from Basic MDM to Advanced Mobile Management. Enforce device passcodes, encryption, selective remote wipe, and require device approval before PlotPath account access. | Protects sensitive client data on lost or stolen devices. Basic MDM is insufficient for a company handling financial data. |
| Application Access Control | Full audit and classification of third-party apps | Removes high-risk apps and limits permissions for low-trust ones. |
| Administrative Governance | Admin training on alert handling, DLP triage, and app vetting | Ensures ongoing vigilance and correct incident response. |
Summary
Security is an operational requirement for a financial operations firm. Our systems and policies are designed to protect confidentiality, integrity, and availability without slowing down day-to-day work. PlotPath maintains a continuous focus on monitoring, refinement, and governance so that our security posture remains strong and aligned with best practices.
If you have questions about how we protect your data or would like further technical detail, our team can walk you through any of the measures described on this page.
