Skip to main content
Plugin Genie Logo Plugin Genie
  • Pricing
  • Help Center
  • Examples
  • Contact Us

Security

This page outlines the security practices in place for the Plugin Genie Microsoft Power Automate app.

If you have a security question not answered here, please contact us.

Certifications

The Microsoft Power Automate app has been reviewed and approved by the monday.com app review team, which includes verification of the security controls listed on this page.

Plugin Genie is a small company and does not currently hold SOC II, ISO 27001, or similar third-party certifications.

Transport Security

All communication between your browser, the app, and our servers is encrypted in transit:

  • HTTPS is enforced across all endpoints with a valid SSL certificate.
  • TLS 1.2 or higher is required for all connections.
  • HTTP Strict Transport Security (HSTS) is enabled with a minimum age of one year, ensuring browsers always use encrypted connections.

Data Security

Your data is protected at rest and within our application:

  • The database is encrypted using AES-256 encryption.
  • monday.com API tokens are encrypted in the database. Encryption keys are stored as environment variables, not in source code or configuration files.
  • All secrets and credentials are stored as environment variables and are never committed to source control.
  • Database queries are parameterized to protect against SQL injection attacks.

Privacy & Data Retention

  • The app does not use tracking cookies.
  • When an account uninstalls the app, all associated data in our database is permanently deleted within 10 days.

Security Questions

If you have a security concern or question, please reach out to us at support@plugingenie.com or through our contact page.

Legal

  • Terms and Conditions
  • Privacy Policy
  • Security

Help Center

  • Getting Started
  • Frequently Asked Questions

Examples

  • SharePoint List Example
  • Microsoft Forms Example

Contact

  • Contact Us
Copyright © 2026 Plugin Genie LLC