Plug N Play

Your data, and what we will not do with it

Including the parts that do not flatter us. You are handing a small company your client list — you should know exactly what that means.

The short answer

Plug N Play stores your data on self-hosted infrastructure in the United States, encrypted in transit and at rest, with encrypted off-site backups. Card numbers are tokenised by the payment gateway and never reach our servers. Your data is never sold and never used to train AI. We do not hold a SOC 2 report.

Your data is yours, and it leaves whenever you want

Every record — clients, animals, appointments, invoices, messages, documents — exports in an open format on demand. No export fee, no notice period, no "contact your account manager". A platform that makes leaving hard is telling you what it thinks of its own product.

We never sell it, and we never train AI on it

Your client list is not a data product and never becomes one. There are no third-party AI services in the platform — the automation is rules the system follows, running on your own data, in your own account. Nothing is shipped to a model vendor for training or inference.

It runs on our own infrastructure, not a chain of vendors

The application, the database, the file storage, the mail server, the phone rail and the error tracking are all self-hosted on infrastructure we control. Fewer companies hold your data because fewer companies are involved.

Encrypted in transit and at rest

TLS on every connection, HTTP/3 end to end. Payment card numbers never touch our servers at all — cards are tokenised by the payment gateway and we store only the vault reference. Bank details for payroll are encrypted with a separate key.

Staff see what their role allows, and it is revocable in one click

Role-based access throughout, and a terminated staff member is default-denied everywhere the moment they are marked terminated — including mail, calendar feeds and the mobile apps. Offboarding is one action, not a checklist somebody forgets.

Backed up off the box

Encrypted backups run to storage separate from the production server, so losing the server does not mean losing the business. Restores are tested, not assumed.

What we have not done

Every vendor in this category publishes a security page. Most of them are a wall of badges. Here is the list we would rather you heard from us than found out during procurement.

No SOC 2 report

We have not completed a SOC 2 Type I or Type II audit. Larger vendors in this category have. If your insurer, franchisor or enterprise client requires one, we cannot satisfy that today and you should say so early.

No ISO 27001, no HITRUST

Not held, not in progress.

No formal penetration-test report to share

The platform runs dependency and secret scanning on every change and an error-tracking pipeline in production, but we do not have a third-party pen-test letter to hand you.

No contractual uptime SLA on the lower plans

We monitor every public surface minute-by-minute and alert on failure, but a credit-backed SLA is an Enterprise conversation, not a published promise.

If any of these is a hard requirement for your business, tell us in the first conversation. We would rather lose the deal than have you discover it in month three.

Questions we get asked

Where is my data physically stored?

On dedicated infrastructure in a United States data centre, with encrypted off-site backups. It is not distributed across a chain of third-party SaaS vendors.

Do you store credit card numbers?

No. Cards are tokenised by the payment gateway (Authorize.net or Stripe, your choice) and we hold only the vault reference needed to charge a saved card. The card number never reaches our servers.

Is my data used to train AI models?

No. There are no third-party AI services in the product at all. What we call automation is rules the system follows on your own data. Nothing is sent to a model vendor.

What happens to my data if I cancel?

You export everything first — that is available to you at any time, not only on the way out. After you confirm you are done, the account is closed and the data is removed on a defined schedule rather than kept indefinitely.

Are you SOC 2 certified?

No. We have not completed a SOC 2 audit. If that is a requirement for you, we are not the right platform yet and we would rather tell you now.

Can I self-host it entirely?

Yes — that is the Full Integration engagement. The platform is deployed on infrastructure you own and control, and you hold the keys.

Something not answered here?

Security questionnaires, DPAs and vendor reviews go to a real person who will tell you plainly whether we can meet the requirement.

info@bucksdogtraining.com

Found a vulnerability? Report it here — we will acknowledge it and we will not come after you for telling us.