Buyer evidence

Security overview

Plainly reduces risk by collecting less. The public calculators and standard embed run in the browser and do not send entered salary or deduction values to Plainly.

Version 1.0Last reviewed 25 July 2026Contact: matthew@plainlyfinance.co.uk

Architecture

Development controls

Changes are developed on a branch, tested in a preview deployment, reviewed through a pull request and merged only after automated checks pass. Statutory changes update dated source files and golden calculation cases together.

Source controlGitHub with protected review workflow
DeploymentVercel preview and production deployments from Git
Dependency reviewAutomated npm audit and scheduled dependency updates
Browser policySelf-only scripts, denied device permissions and route-aware framing controls
Calculation assuranceGolden, invariant and cross-region automated tests
Production monitoringHourly route, asset, content and security-header evidence with visible workflow failure
RecoveryImmutable Git history and deployable prior production commits

Vulnerability and incident reporting

Report a suspected vulnerability tomatthew@plainlyfinance.co.uk. Do not include real employee salary data. Reports are acknowledged within one UK business day for commercial customers and assessed according to severity.

The current product does not claim ISO 27001, SOC 2 certification or penetration-test coverage. These can be scoped for an enterprise engagement where required.

Commercial boundaries

Customer authentication, customer databases, CRM forwarding and private APIs are not part of the standard static embed. Any bespoke integration that changes the data flow receives a separate threat model, data-flow review and order form.