Who builds Ploxir — and who has vetted it

Reviewed & approved byStripe logoStripeAmazon logoAmazon
Listed onSentry logoSentry
STAR Level One: Self-AssessmentSecurity Trust Assurance & Risk

Ploxir rolls up every business you run into one dashboard: combined revenue, combined costs, and a per-business breakdown whenever you want to see which one is carrying the others. That is the whole idea. Everything else — the 80+ integrations, the 2,000+ widgets, the currency conversion — exists to make that one number correct.

The problem it is built for is a specific one. Run several businesses at once and you have a number for each thing and no number for everything: Stripe holds one, an app store the next, analytics a third, ad spend a fourth. The total exists only in your head, recalculated by hand every time you go looking for it.

Ploxir is built in Spain by a team led by Mohammed Chaara — a named, identity-verified person you can look up before you connect anything, rather than a support alias behind a contact form. He runs several businesses of his own, which is where the roll-up came from.

Identity verified by LinkedIn: Mohammed Chaara on LinkedIn, alongside the Ploxir company page.

Read-only by design — and reviewed by Stripe

Connecting Ploxir means granting read-only access to platforms that hold your money — so Stripe, not Ploxir, publishes what that access covers. The Ploxir app is reviewed and approved on the Stripe App Marketplace, where the permission table is Stripe's own: all 12 permissions are read-only. Ploxir cannot move money, issue refunds, or change anything in your Stripe account, and uninstalling from your Stripe dashboard revokes access immediately.

Amazon reviewed it too. Ploxir is approved into the Amazon Selling Partner Appstore under the Finance & Accounting role — read-only, no access to buyer personal data, and disconnectable by the seller at any time. Amazon serves that listing to signed-in sellers, so if you sell on Amazon you can look it up from your own Seller Central account.

On Ploxir's own side: credentials are encrypted with AES-256-GCM before they reach the database, and the key is held in the process environment rather than the database — a database dump alone decrypts nothing. Accounts support two-factor authentication, new-device login alerts, and role-based access across Owner, Admin, Editor and Viewer.

You can archive a source at any time, which stops it syncing and hides its widgets while keeping everything — reconnect the same account and it comes back exactly as it was. You can also delete one permanently, which erases its stored history and cannot be undone; for a Stripe App source that also uninstalls Ploxir on Stripe's side. Deleting a business or your account does the same for everything under it. How the encryption works and how to report a vulnerability are set out on the security page.

What has shipped, and what is running

Every paid plan is free right now, and new integrations and improvements ship weekly. You do not have to take that on faith: the changelog shows exactly what shipped and when, and the status page shows whether it is running right now. Both are generated from the real system, not written by hand.

If a number does not look right, email [email protected]. A wrong number is the one failure this product cannot have, so we triage those ahead of everything else.