Data and access · Private pilot
Your infrastructure stays in your hands.
The product is being built around read-only collection, explicit assessment scope, and evidence you can inspect.
Access boundaries
Plimie will only read provider data needed for enabled checks. It will not change WAF policies, cache settings, DNS, or infrastructure. Customers remain responsible for reviewing and applying recommended actions.
Credentials
Customer credentials are encrypted before storage with AES-256-GCM, a separate encryption secret, and workspace/connection-bound authentication. Tokens are not saved in browser storage or returned by the API. Disconnect removes the stored credential and cancels active scans. An already-started provider read can finish, but cancelled scans cannot append results. Revoke the token separately in the account where you created it.
Evidence and limitations
Configuration, analytics, entitlements, cost, and customer confirmations are distinct evidence sources. Missing permissions and unsupported plans remain visible gaps. An inferred model score cannot create a recommendation by itself.
AI processing
External AI processing is disabled. Scans record that inferred signals are unavailable and continue with deterministic rules. Plimie does not send customer data to an external AI model. Any later model input must be minimized and stripped of credentials, raw responses, IP addresses, cookies, and full URLs.
Scan and report notifications
In-app notices and weekly reports are scoped to your workspace membership. Owners can separately opt in to email their own sign-in address when scans finish or weekly reports are ready. Both email preferences start off. Email contains a generic notice and authenticated link, not evidence, outcomes, or credentials. Opt-out stops pending delivery, but messages already in flight cannot be recalled. Deleting a workspace removes its report, notice, and preference records, not copies already held by email providers or recipient mailboxes.
Retention and deletion
This release is for the invited owner to validate the pilot. Evidence and feedback persist in the application database until the owner deletes the workspace; disconnecting a connection does not delete them. No approved backup or timed-retention duration exists yet. Owners can export their workspace data without provider credentials or sign-in data. Owners can delete a workspace from the workspace page after confirmation; that cancels in-flight scans, wipes stored credentials, and removes the workspace’s records. Legal terms remain unfinished before external customers are admitted. For pilot support, contact the person who invited you to Plimie. The sample assessment is fictional; its interactive feedback is held only in the current page and resets on reload.
Workspace deletion removes the application’s database records and durably queues removal of retained scan-processing state. Cleanup retries keep only instance IDs and operational metadata until the provider acknowledges deletion or absence. Cleanup is asynchronous, not immediate. Database recovery copies are separate; their retention policy and the live cleanup lifecycle must be verified before admitting external customers.