STAR Registry Listing for
Ploxir
Ploxir
Ploxir is a hosted, multi-tenant business dashboard delivered as SaaS. A customer connects the platforms they already use; Ploxir retrieves each platform's metrics on a schedule, or receives them as the platform pushes events, and presents them together — per business, and rolled up across several businesses into one portfolio view.
Delivery: public cloud, multi-tenant, browser-based — no agent, no on-premises component. Current catalogue: ploxir.com/integrations.
Data handled: account and workspace records; each connected source's configuration, with credentials encrypted at rest; and the metric values retrieved from connected platforms. Cardholder data is out of scope — payments are processed entirely by the payment provider and card details never reach Ploxir.
Security posture (control-by-control detail in the accompanying CAIQ self-assessment):
- Connected-platform credentials encrypted at rest with AES-256-GCM; versioned keys held outside the database
- TLS 1.2 or higher in transit
- Least-privilege role-based access control enforced server-side on every mutation; tenant isolation re-verified per request
- Multi-factor authentication with single-use backup codes
- Audit logging of security-sensitive actions
- Nightly integrity-verified backups, replicated offsite; restore rehearsed
- Published vulnerability disclosure policy at /.well-known/security.txt (RFC 9116)
- Self-service data export and deletion

Listed Since: 08/17/2026
STAR Level 1

CAIQ Self-assessment v4.1.0
Offers an industry-accepted way to document what security controls exist in IaaS, PaaS, and SaaS services. It provides a set of Yes/No/NA questions and space to justify the response a cloud consumer and cloud auditor may wish to ask of a cloud provider to ascertain their compliance to the Cloud Controls Matrix (CCM).
Created or renewed 7 days ago, on August 17, 2026.