Security
Last Updated: March 17, 2026

We take the security of your data seriously. This page covers how we protect it, whether you’re planning for your own future or managing plans for clients.
Infrastructure
ProjectionLab runs on Google Cloud Platform and Google Firebase. Application data is stored in Google Cloud Firestore, and the app is served globally through Firebase Hosting. We run automated daily backups and regularly test our restore process.
ProjectionLab is built on Google Cloud infrastructure covered by certifications including SOC 1/2/3 and ISO 27001, which helps provide a strong security foundation for our platform. You can review Google Cloud’s compliance offerings, Firebase security documentation, and encryption documentation. These certifications apply to Google Cloud’s infrastructure and controls rather than ProjectionLab itself.
Encryption
Connections to ProjectionLab use HTTPS with TLS, so data is encrypted in transit between your browser and our servers. Application data stored in Cloud Firestore is encrypted at rest using Google Cloud’s AES-256 encryption.
Authentication & Access
- Sign-in: We use Firebase Authentication with support for email/password and Google sign-in.
- Multi-Factor Authentication: You can add MFA to your account using an authenticator app (TOTP) or SMS.
- Data Isolation: Each user can only access data they are authorized to access. Firestore security rules enforce this at the database level, and backend requests require authentication.
- Internal Access: Admin access on our side is role-based, limited to authorized personnel, and requires MFA.
Privacy & Data Handling
We never sell your data. We do not share your planning data with third parties for advertising or marketing.
We use a small number of third-party service providers to operate ProjectionLab, including Google Cloud for hosting and Paddle for payment processing. For full details, see our Privacy Policy.
Payments
Subscriptions are processed by Paddle. We do not store your credit card number or payment details on our systems.
Account Deletion
You can delete your account at any time from within the app. This removes your account and planning data from our systems. We may retain limited records where required for billing, tax, or legal purposes.
Security Incidents
If we discover unauthorized access to personal information on our systems, we will investigate, respond appropriately, and notify affected users as required by applicable law.
Vulnerability Reporting
We do not run a bug bounty program, and this page does not authorize testing against our systems. If you find a security issue, please email security@projectionlab.com with enough detail for us to investigate.
For Advisors and Compliance Teams
If your review requires something not covered on this page, contact security@projectionlab.com.
Contact
- Security: security@projectionlab.com
- Privacy: privacy@projectionlab.com
- Support: support@projectionlab.com
This page reflects current practices and may be updated from time to time.