Security

Plaza is designed to ensure that your content is accessible only to your customers. The system operates based on three components: your store (with the SimpleDRM plugin), the Plaza Reader, and our website.

Both the Reader and your store authenticate on our website. That way, every time a customer visits your store to download content, the plugin verifies the authenticity of the request by contacting our server. The information flow is as follows:

  1. The Reader authenticates with the Plaza server when the user enters and validates their email address.
  2. Your store activates the plugin and registers with our server
  3. When the Reader wants to download content from your store, it first notifies the Plaza server of its intentions, which returns a unique code
  4. It then sends the request to your store, attaching the code
  5. The SimpleDRM plugin requests confirmation from the Plaza server that the request actually comes from a legitimate Reader belonging to your customer.
  6. The Plaza server returns the result of the verification, either authorizing or denying the request.
  7. The content is downloaded in encrypted form to your customer’s Reader.

All content is transmitted in encrypted form and does not pass through our servers. It is stored in encrypted form on the Reader, so your customer cannot copy or share it—only enjoy it within the app itself. We use AES-256 encryption and the mandatory secure HTTPS protocol for communications.

For any additional details, please feel free to contact us.