Security
Last updated: 6 August 2026
We take the security of your account and payments seriously. Here's what's in place, in plain language.
Account security
- Passwords are hashed with Argon2id, the current industry-recommended standard — we never store or see your actual password.
- Sign-in is protected by rate limiting and, for phone/email verification, time-limited one-time codes.
- Sessions use short-lived access tokens with automatic, rotating refresh tokens — if a stolen refresh token is ever reused after rotation, all of that account's sessions are automatically revoked.
Payment security
All payments are processed by Razorpay, a licensed payment aggregator regulated by the Reserve Bank of India. Your card and bank details are handled entirely by Razorpay's PCI-DSS-compliant infrastructure — Plixico never receives or stores your full card number, CVV, or bank credentials.
Data in transit & at rest
All traffic between your browser/app and Plixico is encrypted over HTTPS. Our database is hosted on managed infrastructure with encryption at rest.
Reporting a security issue
If you've found a security vulnerability, please report it responsibly to security@plixico.com rather than disclosing it publicly. We investigate every report and will acknowledge receipt within 48 hours.