Ploto
For IT Departments

Ploto Technical Information for Deployment Review

A summary of Ploto's execution privileges, stored data, external communication, AI integration, encryption and uninstall behavior.

Last updated: 2026-09-24
Contact: hiroki.lab@outlook.com

Review Summary

Distribution Microsoft Store (Product ID: 9N4NJNMT2B77)
Account Not required. No sign-in feature
Privileges Runs as the signed-in user. No elevation prompt
Normal use No connection required. Creating, editing and saving work offline
Project storage A .ploto file (SQLite) in a location you choose
Cloud sync No Ploto-operated sync or upload feature
AI integration Requires user permission. AI operates only via MCP (named pipe) or a loopback API on the same PC; content it reads is sent to the AI service the user subscribes to
Usage tracking No in-app telemetry, ads or behavioral tracking
Encryption at rest No app-level encryption. Protected by the OS and the storage location

1. Product and Document Information

This document provides technical information about Ploto (the app), a project management application for Windows, for review by IT departments. The URL of this page, or a printed or PDF copy of it, may be used in your organization's application review process.

  • Product name: Ploto
  • Supported OS: Windows 10 and Windows 11
  • Distribution: Microsoft Store
  • Microsoft Store Product ID: 9N4NJNMT2B77
  • Publisher shown in the Store: hiroki.lab (individual developer)
  • Official site: https://ploto-app.com/
  • Contact: hiroki.lab@outlook.com

Whether the app is suitable for your business data is a decision for your organization, based on your data classification, the access controls on the devices and storage locations involved, your backup arrangements and your internal standards for application use.

2. Distribution, Execution and Privileges

The app is a desktop application built with Rust, Tauri and Windows WebView2, distributed and updated as an MSIX package through the Microsoft Store. It does not request elevation to administrator privileges during normal operation.

The MSIX manifest declares runFullTrust so that the app can operate as a desktop application. This means it runs with the same privileges as the signed-in user; it does not grant administrator rights automatically. The app does not create Windows services, startup entries or scheduled tasks.

When the AI Terminal is used, the app starts PowerShell, Git Bash or WSL as a child process with the signed-in user's privileges, and only while the terminal is shown on screen. The built-in PowerShell is started with -ExecutionPolicy Bypass for that process only; the device and user execution policies are not changed (execution policies set by Group Policy take precedence over this option). The package also includes the execution alias ploto-mcp.exe, which AI clients use to connect to Ploto. It is a connection-only mode started by the AI client; it has no window and only relays requests to the main Ploto app.

3. Microsoft Defender and Application Control

Even for an app certified and distributed through the Microsoft Store, Microsoft Defender or application control settings on your organization’s devices may prevent installation, startup or file saving. This app includes native executables built with Rust and Tauri. Apps of this kind are more likely to be caught by heuristic detection or prevalence-based blocking while a release is new and has little execution history (prevalence). Store certification does not exempt an app from controls your organization configures.

Situations to expect:

  • Heuristic false positives from antivirus: Cloud-delivered machine-learning verdicts may quarantine a new executable under a generic detection name such as Wacatac or Wacapew. This often resolves after a security intelligence update.
  • Attack surface reduction (ASR) rules: If "Block executable files from running unless they meet a prevalence, age, or trusted list criterion" is enabled, a newly released version may be blocked.
  • Controlled folder access: Writes to protected folders such as Documents or Desktop may be denied, which surfaces as an error when saving a .ploto file.
  • WDAC and AppLocker: If the signer or the package is not allowed, the MSIX package will not start at all.
  • SmartScreen: Normally not triggered for installs through the Microsoft Store, but a warning may appear depending on your policy configuration.

Package identity (use these values in your allow rules):

  • Package name (Package/Identity/Name): hiroki.lab.Ploto
  • Package family name (PFN): hiroki.lab.Ploto_va563q7jg714e
  • Publisher (Package/Identity/Publisher): CN=AB453F36-8F71-4C99-BB89-582301D0AE38
  • Package SID (for firewall rules): S-1-15-2-1517193112-901780427-1522304721-281083616-2611253276-1887865729-3282081193

These values can also be read on a device where the app is installed, by running Get-AppxPackage in PowerShell.

PackageFullName and the installation path change with every version. For application-control allow rules, use the package name, PFN and publisher information above rather than a path.

When considering whether to allow the app in your organization:

  • WDAC and AppLocker: Refer to the installed package or MSIX and, in accordance with your organization's application-control standards, create a package rule whose Publisher and Package name match this app. Configure the range of versions allowed for updates in accordance with your organization's change-management policy as well.
  • Microsoft Defender and ASR: If a detection or block occurs, review the detection name, affected file, source, package signature and records in the management console, and respond according to your organization's procedures. If you determine that a protection setting must be changed or an exception is required, obtain approval from the security administrator and limit it to this app, the minimum scope and the necessary period.
  • Controlled folder access: If saving is denied, first use a storage location approved by your organization. If the app must be added to the allow list, verify that the package was obtained from the Microsoft Store and confirm its signature, then follow your organization's approval procedure.
  • Reporting a false positive: If you conclude that a detection is incorrect, you can report it through Microsoft’s sample submission form. If you send the detection name, the Defender version and the app version to the contact below, the provider will report it as well.

This app does not create Windows services, startup entries or scheduled tasks (see section 2). A detection is therefore likely to be a heuristic false positive, but how you handle it should follow your organization’s security operations standards.

4. File Access

Technically, the app can read and write any file the running user has permission to access. As a matter of product behavior, it works with the files the user selects to open, save, import or export, the app's local settings and working files, and lock files used to prevent simultaneous editing.

There is no feature that scans the device's files exhaustively, that continuously monitors an arbitrary folder, or that automatically uploads project files anywhere. Read and write access to storage locations follows the access controls enforced by Windows and by your file servers.

5. Files and Information Stored

Projects: Saved as a .ploto file in a location the user chooses. The format is a standard SQLite database containing tasks, assignee names, schedules, to-dos, notes, whiteboards, settings and similar data. Templates, import sources and exported files such as Excel workbooks are also read and written in locations the user selects.

Working copy: While a project is open, a working copy of the entire project is created in the app's local data area managed by Windows. It is deleted when the project is closed normally, and a copy left behind by an abnormal termination is removed on the next startup where possible.

Lock file: While a project is being edited, a <name of the .ploto file>.lock file is created in the same location as the project. It records the Windows user name, computer name, process ID, start time and update time, and is deleted on normal exit. On a shared folder it can be read by any user or administrator with access to that location.

Local settings: UI preferences, the license key, notice display state, editor settings and similar values are stored in the app's local data area managed by Windows. Recently opened files are stored in %USERPROFILE%\.ploto\recent-files.json as up to 10 paths with their last access times. Some auxiliary settings files are stored in %USERPROFILE%\.ploto. A random identifier may be stored so that the app can tell which installation created a project. This value contains no OS device identifiers or personal information and is not transmitted externally.

AI integration: The AI integration consent status, trial usage count, AI Terminal license code and Store verification time are stored in ai-access.v1 in the app's local data area, protected with Windows DPAPI. Each time AI integration is enabled, the working folder for AI clients %USERPROFILE%\.ploto\ai (and also %USERPROFILE%\.ploto\ai-wsl when WSL is used) is rewritten with MCP connection settings (.mcp.json, opencode.json, .vscode/mcp.json, .cursor/mcp.json, .gemini/settings.json), instructions for AI (AGENTS.md, CLAUDE.md, GEMINI.md, PLOTO.md, references/) and connection scripts (ploto.ps1, ploto.cmd, ploto.sh). None of them contain credentials. See Section 7 for details.

6. Network Communication and Allowlist Candidates

No internet connection is required to create, edit or save projects, or to verify a purchased license. The in-app WebView is configured with a Content Security Policy that prevents it from connecting to external sites. External pages open in the default web browser or in the Microsoft Store, and only when the user chooses to open them.

For AI integration, the app accepts connections only from AI clients on the same PC (MCP over a named pipe and loopback HTTP to 127.0.0.1), and the app itself does not perform any AI-related external communication. See Section 7 for details of the connection methods. Communication from the AI CLI to the AI service (such as each AI service's API endpoints) follows the specifications of the AI CLI installed by the user and the organization's network settings.

If your organization restricts outbound traffic, the main destinations to consider are apps.microsoft.com (product page and reviews), buy.stripe.com and checkout.stripe.com (web purchase), ploto-v2-license-webhook.vercel.app (purchase completion and connectivity check), docs.google.com (optional forms), ploto-app.com (official site) and hiroking-ocean.github.io (manual and this document). The CDN, authentication and font domains that each service depends on are determined by those providers.

Platform traffic from Windows Update, the Microsoft Store, Windows Error Reporting and similar components follows the Microsoft product settings applied to the device and to your organization.

7. AI Integration (AI Terminal and MCP)

The AI Terminal lets AI CLIs that the user has installed on this PC and signed in to under their own subscription (such as Claude Code, Codex, Gemini CLI, OpenCode and GitHub Copilot) read and edit the project open in Ploto. The app does not bundle or automatically install any AI CLI, and it does not handle AI service accounts or API keys.

Connection methods: The AI operates Ploto only through one of the following routes. Both are limited to connections within the same PC and cannot be reached from other devices on the network. There is no API that gives the AI direct access to Ploto's project files or database.

  • MCP (primary route): The AI client starts ploto-mcp.exe --mcp-stdio (an MSIX app execution alias) as an MCP server and communicates with it over standard input and output. This process has no window and only relays: it forwards requests to the running Ploto app over the Windows named pipe \\.\pipe\LOCAL\ploto-mcp-<64-character identifier>. The identifier is a fixed value derived from the user profile path and the app identifier. The pipe restricts access to its creator (the same Windows user), rejects remote clients, and is created exclusively to prevent another process from claiming the same name first. No token is used. Up to 16 simultaneous connections are allowed, and each request is limited to 64 KiB.
  • Terminal API (fallback route): For AI clients that do not read MCP settings, ploto.ps1, ploto.cmd and ploto.sh send requests over HTTP from the built-in terminal. The app listens only on a dynamic port on 127.0.0.1 and is not exposed on external interfaces. Each request requires a random 256-bit Bearer token, which is held only in memory and passed only through the built-in terminal's environment variables (it is never written to a file). The Host header is checked, and requests from browsers (with an Origin or cross-site) are rejected. Request bodies are limited to 64 KiB. The token is revoked when the project is switched or closed, or when the app exits.
  • Common controls: Both routes go through the same internal processing in Ploto, so consent checks, read-only start, edit permission, the inability to save, and trial counting apply in the same way. Operations are processed one at a time, with a 30-second response timeout. There is no API that runs arbitrary SQL, file operations or shell commands.
  • When connections are accepted: Both routes start listening when the Ploto window starts, but project operations are rejected until the user consents. While Ploto is not running, the MCP relay process started by the AI client stays running, answers requests by reporting that Ploto is not running, and reconnects when Ploto starts again. MCP cannot launch Ploto, open files or change permissions.
  • Windows Firewall: Incoming connections are limited to loopback and the named pipe, so no inbound firewall rule is required. Outbound communication from the AI CLI to the AI service follows the AI CLI's specifications.

Data flow: Project content read by the AI (such as task names, assignee names, schedules, notes, ToDos and tags) is sent through the AI CLI to the AI service provider chosen by the user. This transmission does not pass through servers operated by the provider of Ploto. Handling such as use for training, retention period and processing region is governed by the agreement between the user and the AI service provider. If business data will be handled, inform users that they must use AI services and plans approved by the organization.

Permissions and scope of operations:

  • Consent is requested the first time the terminal is shown, and project operations are rejected until it is granted. Consent is stored on the device and is not requested again.
  • AI operations always start in read-only mode. Editing is possible only when the user turns on the switch or approves an edit permission request from the AI. Permission is revoked when the file is switched or closed.
  • Edits by the AI are applied only to the working data on screen; the AI cannot save the .ploto file. Saving is done by the user in the app. Edits can be reverted with Ploto's normal Undo.
  • Ploto's API does not accept arbitrary SQL or shell execution. However, the built-in terminal is a shell with the user's privileges, and the permissions above do not restrict file operations or commands that the AI CLI performs in the shell. Those follow the AI CLI's permission settings and the user's approvals.
  • The operation history shows only method names and success or failure for up to 30 entries on screen and is not saved to a file. Ploto does not store or transmit conversations, terminal output or operation content.

Writes to AI client settings: Apart from the working folder (Section 5), Ploto writes its MCP connection settings and a short connection guide (Skill) to AI clients' user settings only in the following cases. Only Ploto's entries are written; other settings are not changed.

  • Codex: Because Codex does not read project-level settings, Ploto registers itself automatically in %USERPROFILE%\.codex\config.toml (or under CODEX_HOME if set) and %USERPROFILE%\.agents\skills each time AI integration is enabled.
  • Others (Claude Code, Cursor, Gemini CLI, Antigravity, OpenCode, VS Code / Copilot): Written only when the user clicks the register button in the connection settings screen. Nothing is written for clients whose settings folder does not exist, and Claude Code's ~/.claude.json is updated only if it already exists.
  • The destination paths are shown on screen, and registrations can be removed from the same screen.

Instructions given to AI: Ploto gives the AI instructions for operating the app correctly (procedures, API specifications, checks before writing, not editing on guesswork, not searching for credentials or the database, and so on) through the MCP initialization response and as text files in the working folder. The instructions guide the AI's behavior; the security boundary is enforced by the permission, read-only and no-save mechanisms described above. The full text can be viewed and copied on the separate page "Instructions Ploto Gives to AI".

Trial and license: The trial accepts up to 60 API/MCP operations in total. The count and license are managed on the device, and usage is not sent to the provider of Ploto. Purchases of the Store version are verified through Microsoft Store.

Disabling in an organization: Setting the system or user environment variable PLOTO_DISABLE_AUTOMATION=1 makes the app refuse to enable AI integration. This is an in-app setting and does not replace application control or the organization's AI usage standards. Manage whether AI CLIs themselves may be used through the organization's device management and network controls.

8. External Services and Transmitted Information

Microsoft: Handles distribution, updates, in-Store purchases, reviews and OS diagnostics. The provider of Ploto may review aggregated distribution and quality information in Partner Center.

Stripe: When a user starts a web purchase, Stripe processes payment details, the purchaser's email address, the product, amount, currency and date, connection information, and the device hash described in section 3.2 of the Privacy Policy. Card numbers and similar details are handled directly by Stripe.

Vercel: Receives purchase completion information from Stripe and generates a signed license key. No dedicated purchaser database is maintained, although operational logs may be processed.

Resend: Sends the license key to the purchaser's email address, processing the recipient address, message body and delivery information.

Google: Processes form responses if a user chooses to submit an optional form. The official website uses Google Analytics 4. Google Analytics is not embedded in the app itself.

GitHub: Delivers the official site, the manual and this document via GitHub Pages, and may process standard access information.

AI service chosen by the user: When the AI Terminal is used, the AI CLI sends project content to that AI service (Section 7). This is based on the agreement between the user and that provider, which is not a processor acting on behalf of the provider of Ploto.

9. Encryption, Authentication and Safety Management

.ploto files, working copies and lock files are not encrypted at rest by Ploto itself. If you handle confidential information, configure protection on your side using OS features such as BitLocker or EFS, ACLs on the storage location, share permissions, backups and controls on taking data off site.

Pro licenses are verified on the device using an Ed25519 digital signature. This confirms that the license key is genuine; it is not a feature that encrypts projects. Payment details for web purchases are entered on Stripe-hosted pages, and the license issuing webhook verifies Stripe's signature before processing. Private keys and the API keys of external services are not bundled in the application.

Your organization should apply least-privilege Windows accounts, device encryption, access controls on storage locations, backups, anti-malware protection, updates for the OS and Store apps, and restrictions on entering confidential information into external forms.

10. Uninstallation and Residual Data

Uninstalling the Microsoft Store version normally removes the app's local data area managed by Windows. Projects, templates, import sources and exported files in locations chosen by the user, along with %USERPROFILE%\.ploto (including the AI working folders ai and ai-wsl), are not removed. To delete everything, the user or the device administrator should remove them after confirming that the necessary backups exist.

Ploto's MCP settings and Skill registered in AI clients' user settings for AI integration are also not removed on uninstall. Before uninstalling, remove them from Ploto's connection settings screen, or delete the block from # >>> ploto MCP >>> to # <<< ploto MCP <<< in config.toml, the ploto entries in JSON settings, and ploto-control in each skills folder.

A working copy or lock file may remain after an abnormal termination or a permissions problem. Delete a lock file only after confirming that nobody is currently editing the project it refers to.

11. Contact and Enterprise Deployment Questions

For questions about this document, the handling of information, security specifications, review for deployment by a company or organization, purchase records or licenses, please use the contact below. If your organization uses a standard assessment questionnaire, please send the questions in the body of an email or as an ordinary document.

If you find a vulnerability or a concern about how information is handled, please contact the email address below rather than posting publicly.

hiroki.lab@outlook.com
Provider
Hiroki Tanaka(individual developer, trading as hiroki.lab)
Location
Chiba, Japan
Response time
Usually within 3 business days(Japan business days)
Languages
Japanese and English