The P(rogrammable)law Company

Plaw

Security

Two things live here: how this website is built, and how Plaw handles customer data. Found a vulnerability? Email [email protected]. We reply to every report within three business days.

This website

plaw.io is a static site served by Cloudflare over HTTPS. There are no accounts, no login, and no payments. The only scripts are the background animation and the booking embed on /meet. The site itself stores nothing you type; the booking embed on /meet sends your details to us and Cal.com, as the privacy page describes. That keeps the attack surface small on purpose.

Reporting a vulnerability

We publish a security.txt. Send reports to [email protected]. We tell you what we plan to do about the finding. There is no bug bounty. Real findings get fixed promptly, and credited if you want credit.

Customer data

The website is the small part. Guddun works inside customer businesses, and that touches schedules, records, and customer and job information. Each customer’s agreement states what we access, what we store, and for how long. Every agent action passes through Veto first: anything that moves money, commits the business, or reaches a customer waits for a person to approve it.