Security

Last updated: 6 August 2026

We take the security of your account and payments seriously. Here's what's in place, in plain language.

Account security

  • Passwords are hashed with Argon2id, the current industry-recommended standard — we never store or see your actual password.
  • Sign-in is protected by rate limiting and, for phone/email verification, time-limited one-time codes.
  • Sessions use short-lived access tokens with automatic, rotating refresh tokens — if a stolen refresh token is ever reused after rotation, all of that account's sessions are automatically revoked.

Payment security

All payments are processed by Razorpay, a licensed payment aggregator regulated by the Reserve Bank of India. Your card and bank details are handled entirely by Razorpay's PCI-DSS-compliant infrastructure — Plixico never receives or stores your full card number, CVV, or bank credentials.

Data in transit & at rest

All traffic between your browser/app and Plixico is encrypted over HTTPS. Our database is hosted on managed infrastructure with encryption at rest.

Reporting a security issue

If you've found a security vulnerability, please report it responsibly to security@plixico.com rather than disclosing it publicly. We investigate every report and will acknowledge receipt within 48 hours.