Platform · Security & Deployment
Runs inside your rules, not around them.
Plant an App runs in our cloud, in yours, or in your own data center, and it’s the same platform in each. It works within the controls your security team already enforces, records what happens, and leaves you to decide when anything changes.
Stall
Security review is where platforms stall.
The pilot works. Then production brings the questions: where it runs, who signs in, what’s recorded, and who decides when it changes.
- 1
It only runs in its own cloud.
Your data has to move to the vendor’s environment, where your hosting rules don’t reach.
- 2
It needs exceptions.
Your standards for sign-in, networks, and encryption bend to fit the platform.
- 3
No one can see inside.
There’s no record of who signed in, what was called, or what changed. Nothing to show an auditor.
- 4
It changes without warning.
The vendor upgrades on its own schedule, and your team finds out in production.
The platform fits your rules.Not the other way round.
Choose
Our cloud, your cloud, or your own data center.
Plant an App runs where your rules say it has to, and it’s the same platform in each place, so nothing is rebuilt if the answer changes later.
- Our cloud
Hosted by Plant an App.
On AWS or Azure, in the US or the EU. We run the hosting, backups, monitoring, and security.
Who runs itWe do, and your team schedules upgrades - Your cloud
In your own account.
On AWS, Azure, or Google Cloud, including government clouds, under your own policies.
Who runs itYour team or your integrator - Your data center
On your own servers.
On Windows servers and SQL Server inside your network, fully offline where the network has no internet access.
Who runs itYour team or your integrator
Everywhere, it runs on Windows, .NET, and SQL Server. In your own environment, application data stays there. It leaves only through the integrations you build.
Protect
Built into the platform, not added to each application.
The protections a security team checks for come with the platform, so every application starts with them, not when someone remembers to add them.
Encrypted on the wire.
HTTPS is enforced on every request, including behind a load balancer.
Encrypted where it’s stored.
Secrets and connection details are stored encrypted and masked, and the database can use SQL Server’s own encryption.
Cryptography for regulated environments.
A FIPS-compliant cryptography mode, where your standards require it.
Forged requests are refused.
Requests that change data carry anti-forgery checks, so another site can’t act in a user’s name.
Input stays input.
SQL runs with bound parameters, output is encoded for where it appears, and uploads accept only the file types and sizes you set.
Passwords stay secret.
Stored only as hashes, with lockout after failed attempts. Or no passwords at all, with your identity provider or passkeys.
Sign-in and roles, permissions on data, and API security each have their own page: Identity & Access, Data, and Integration & Connectors.
Every application inherits the baseline.Your team sets the rules on top of it.
Record
Who did what, and when, is on record.
When an auditor asks who did what, the answer comes from the platform, not from someone’s memory.
ActivityPermitting system · this morning
- 08:58Sign-inA. Moreno · through your identity provider
- 09:04API callInspections API · scheduling system · 200 · 84 ms
- 09:15RecordApplication 0187 · status In review → Approved · A. Moreno
- 09:31ConfigurationWorkflow “Issue permit” changed · J. Chen
- 09:40Sign-in failedUnknown account · locked after repeated attempts
Sign-ins and system events.
Every sign-in, every failed attempt, and every error, in one log.
Every API call.
Who called, from where, with what result, and how long it took, kept for as long as you decide.
Every configuration change.
Which part of the application changed, who changed it, and when.
Every record, where you need it.
Every row stamps who created and last changed it. Where your rules ask for more, a full history with before and after values is added with low-code.
Logs are written as structured files, so your own log collector can send them to the tools your security team already watches.
Scale
More servers, one application.
One server is enough to start. As the load grows, more servers join behind a load balancer, and the application behaves as if there were one.
Every server serves users.
Add servers behind your load balancer, all of them active at once, with their caches kept in sync.
Scheduled work runs once.
One server takes the scheduled jobs, so a nightly job never runs twice, however many servers there are.
One search index for all.
One server keeps the search index current, and every server answers from it.
10M+ financial transactions a month.30,000+ users. One production system.
Operate
Upgrades when you’re ready.
Wherever it runs, upgrades stay with your team, so they can test your applications against the new version before anything reaches production. On our cloud, we run everything else: the hosting, backups, monitoring, and security.
Checked before it starts.
The platform checks its prerequisites, and a health dashboard holds the upgrade until configuration problems are fixed.
Tested before production.
Upgrade a test environment first, run your QA and acceptance tests, then schedule production.
Backed up on a schedule.
Database and site backups run as scheduled jobs, alongside the backup tools you already use.
While an upgrade runs, users see a maintenance page and administrators follow its progress.
Your release calendar.Not ours.
Prove
Evidence your security team can check.
A security review needs more than a feature list. Your team gets the reports, the tests, and the answers it asks for.
- SOC 2 Type II
- ISO 27001
Independently audited.
Plant an App’s security practices are audited under SOC 2 Type II and certified to ISO 27001.
Tested from the outside.
Penetration test reports, shared with your security team.
Answered with you.
We work through your security questionnaire with your team, from architecture to operations.
Related capabilities
Bring your security questionnaire.We’ll answer it with you.
Talk to us about where your applications have to run, the standards they have to meet, and the review they have to pass, and see how Plant an App fits inside them.