Separate access controls are enforced at each layer of infrastructure. Multi-factor authentication is required for access to Plaid infrastructure. All application and user access logs are stored centrally and monitored.
Plaid regularly undergoes both internal and external network penetration tests, third-party code reviews, and PCI re-certification. Plaid has also completed a SOC 2 report. If you have any questions, please email us at firstname.lastname@example.org.
The Plaid API only allows client requests using strong TLS protocols and ciphers. Communication between Plaid infrastructure and financial institutions is transmitted over encrypted tunnels. All client communication with Plaid's API utilizes cryptographically hashed headers and timestamps to verify authenticity.
If you think that you have found a security issue, please contact us at email@example.com. We take all reports seriously. Please do not publicly disclose the issue until we’ve addressed it.