> ## Documentation Index
> Fetch the complete documentation index at: https://docs.plantpredict.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Compliance

> Independent third-party security attestations, certifications, and security practices for the PlantPredict platform

PlantPredict is designed with security, reliability, and operational transparency as core principles. Our platform follows established security practices and undergoes independent third-party assessments to validate the effectiveness of our controls.

<div className="flex flex-wrap items-center justify-center gap-12 my-10">
  <div className="flex flex-col items-center text-center">
    <img src="https://mintcdn.com/terabaseenergy/6wfUfxOlKDXvHoV3/images/compliance-aicpa-soc-logo.png?fit=max&auto=format&n=6wfUfxOlKDXvHoV3&q=85&s=8a673b822d76ef53734b438daa0b81fa" alt="AICPA SOC 2 Type II" style={{ height: "210px", marginBottom: "0.75rem" }} width="223" height="225" data-path="images/compliance-aicpa-soc-logo.png" />

    <p className="font-semibold">SOC 2 Type II</p>
  </div>

  <div className="flex flex-col items-center text-center">
    <img src="https://mintcdn.com/terabaseenergy/6wfUfxOlKDXvHoV3/images/compliance-cyber-verify-logo.png?fit=max&auto=format&n=6wfUfxOlKDXvHoV3&q=85&s=758d5719d44ce5b6ef97eb87050bc36d" alt="MSPAlliance Cyber Verify Level 3" style={{ height: "210px", marginBottom: "0.75rem" }} width="228" height="230" data-path="images/compliance-cyber-verify-logo.png" />

    <p className="font-semibold">MSPAlliance Cyber Verify™ Level 3</p>
  </div>
</div>

<Info>
  Both assessments are performed in accordance with industry-leading frameworks: the [AICPA Trust Services Criteria](https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2) (SOC 2) and the [MSPAlliance® Unified Certification Standard™](https://mspalliance.com/cyber-verify/) (UCS) for Cloud and Managed Service Providers.
</Info>

***

## Independent Assessments

<CardGroup cols={2}>
  <Card icon="shield-check">
    <div style={{color: "#086EC1", fontSize: "1.5rem", fontWeight: 600, marginTop: "0.25rem", marginBottom: "0.75rem"}}>SOC 2 Type II</div>

    PlantPredict has completed a **SOC 2 Type II** examination covering controls related to:

    * **Security**
    * **Availability**
    * **Confidentiality**

    The assessment evaluates the design and operating effectiveness of controls over a defined review period and helps ensure that PlantPredict maintains effective operational and technical safeguards.

    <Note>
      SOC 2 Type II reports are available to qualified customers and prospects under NDA.
    </Note>
  </Card>

  <Card icon="badge-check">
    <div style={{color: "#086EC1", fontSize: "1.5rem", fontWeight: 600, marginTop: "0.25rem", marginBottom: "0.75rem"}}>MSPAlliance Cyber Verify™ Level 3</div>

    PlantPredict has also completed the **MSPAlliance Cyber Verify™ Level 3** assessment, an independent verification program for cloud and managed service providers. The assessment evaluates operational and security practices across governance, change management, service operations, information security, backup and recovery, and related controls.

    Unlike point-in-time certifications, **Cyber Verify Level 3** includes testing over a defined review period to validate that controls are operating effectively.

    <Note>
      Cyber Verify Level 3 reports are available upon request for qualified security reviews and due diligence processes.
    </Note>
  </Card>
</CardGroup>

***

## Security Practices

PlantPredict maintains layered administrative, technical, and operational safeguards including:

<CardGroup cols={1}>
  <Card title="Multi-Factor Authentication (MFA)" icon="user-shield" horizontal>
    MFA is supported for user authentication to help protect against unauthorized account access.
  </Card>

  <Card title="Role-Based Access Control (RBAC)" icon="user-lock" horizontal>
    RBAC restricts access to data and administrative functions based on user role and organizational membership.
  </Card>

  <Card title="Encryption at Rest & in Transit" icon="lock" horizontal>
    Customer data is encrypted in transit using TLS and at rest using industry-standard cryptographic algorithms.
  </Card>

  <Card title="Secure Cloud Infrastructure" icon="cloud" horizontal>
    PlantPredict runs on enterprise-grade cloud infrastructure with hardened network and platform controls.
  </Card>

  <Card title="Backup & Recovery Procedures" icon="database" horizontal>
    Automated backup and recovery procedures support data durability and business-continuity objectives.
  </Card>

  <Card title="Change Management & Security Policies" icon="clipboard-list" horizontal>
    Structured change management and documented security policies govern platform operations and updates.
  </Card>
</CardGroup>

***

## Cloud Infrastructure

PlantPredict leverages enterprise-grade cloud infrastructure providers to support **scalability**, **resiliency**, and **security** for customer workloads. The underlying infrastructure providers maintain their own independent compliance programs (e.g., SOC, ISO 27001) that complement PlantPredict's platform-level attestations.

<CardGroup cols={2}>
  <Card title="PlantPredict Core Services" icon="microsoft" href="https://servicetrust.microsoft.com/DocumentPage/1be7b58c-ecff-4e91-8122-a4886b1d06c5">
    Run on **Microsoft Azure**.

    See the [Microsoft Azure ISO 27001 certification](https://servicetrust.microsoft.com/DocumentPage/1be7b58c-ecff-4e91-8122-a4886b1d06c5).
  </Card>

  <Card title="PlantPredict Pro Services" icon="aws" href="https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/certification/compliance/iso_27001_global_certification.pdf">
    Run on **Amazon Web Services (AWS)**.

    See the [AWS ISO 27001 certificate](https://d1.awsstatic.com/onedam/marketing-channels/website/aws/en_US/certification/compliance/iso_27001_global_certification.pdf).
  </Card>
</CardGroup>

***

## Requesting Compliance Documentation

The following materials are available to qualified customers and prospects during security review processes:

| Document                         | Availability                                          |
| -------------------------------- | ----------------------------------------------------- |
| **Cyber Verify™ Level 3 Report** | Available without NDA through controlled distribution |
| **SOC 2 Type II Report**         | Available under NDA                                   |

<Card title="Request Compliance Documentation" icon="envelope" href="mailto:support@plantpredict.com">
  To request compliance documentation or coordinate a security review, contact **[support@plantpredict.com](mailto:support@plantpredict.com)**.
</Card>

<Note>
  These attestations apply specifically to the PlantPredict platform and associated operational services.
</Note>
