Security & deployment
Your designs stay where your security policy says they go.
Some labs are happy with a hosted service. Some print parts that can't leave the building. Pluraprint runs either way, with the same features, the same access controls and the same audit trail.
Hosted
We run it for you.
- Your own deployment, not a shared tenant
- We handle updates and upkeep
- An agent on your network connects the printers
Self-hosted
On your servers, your rules.
- Docker Compose on hardware or cloud you control
- Your database, your object storage, your backups
- You decide when to upgrade
Air-gapped
No internet. At all.
- Runs on a network with no route out
- No dependency on the public internet
- Updates delivered and installed by hand
How Pluraprint protects a 3D printing operation
Uploaded design and print files are encrypted at rest, and Pluraprint checks that its storage is encrypted before it will use it. Connections between the app, its services, file storage and the printer agents use TLS. Printer access codes and sign-in secrets are encrypted separately before they're stored.
Access is controlled by roles and permissions, with single sign-on for organizations that manage identity centrally. The audit trail records who changed what, and air-gapped deployment is there when data can't leave an isolated network.
Protection
What's in place, in every deployment.
Encrypted file storage
Uploaded files, thumbnails and snapshots are stored encrypted.
TLS in transit
Between the app, its services, storage and on-site agents.
Short-lived file links
Files are handed out through expiring links, never public URLs.
Encrypted secrets
Printer access codes and sign-in tokens are encrypted before storage. API keys can't be read back.
Roles & permissions
Roles built from individual permissions, global or per site.
Single sign-on
SAML, OAuth and OpenID Connect, and CAS.
Tamper-evident audit log
Setting, permission and approval changes, with who and when.
Backups & retention
Scheduled backups for self-hosted installs, and automatic deletion of old jobs.
Principles
How we think about your data.
- Least privilege by default
- Roles start with what a job needs. Everything else stays out of sight.
- Your data is yours
- Never sold, never used to train models. Self-host and it never leaves your network.
- Defense in depth
- Encryption, TLS, access control, network boundaries and audit logging each cover a different risk.
- Everything attributed
- Admin changes and job decisions are tied to the account that made them.
FAQ
Security & deployment questions
What IT and security teams ask before they sign off.
Something else? Ask us directly.
Can Pluraprint run without internet access?
Yes. Pluraprint can run on your own servers behind a firewall, or on an air-gapped network with no internet connection at all. The application, database and file storage all stay inside your network, and updates are installed when you choose.
How does Pluraprint protect uploaded design files?
Uploaded files are encrypted at rest, and Pluraprint checks that its file storage is encrypted before it will use it. Traffic between its parts uses TLS. Printer access codes and sign-in secrets are encrypted separately, and roles control who can see what.
Does Pluraprint keep an audit trail?
Yes. Changes to settings, roles, rules and approvals are recorded with who made them and when. Each print job also keeps its own history, from upload to pickup.
Do you use our data to train AI models?
No. Customer data is never sold or used to train models. If you self-host, the data never leaves infrastructure you run.
Does Pluraprint support single sign-on?
Yes. Pluraprint supports SAML, OAuth and OpenID Connect, and CAS, so people sign in with the account they already use. Roles inside Pluraprint still decide what each person can do.
Bring your security questionnaire.
Send us your hosting constraints or your review checklist. We'll walk your team through architecture, storage, identity and the update path.