Security

Last Updated: August 12, 2026

Security

We take the security of your data seriously. This page covers how we protect it, whether you’re planning for your own future or managing plans for clients.

Security at a Glance

  • Bank-level encryption: data is encrypted in transit (HTTPS with TLS) and at rest (AES-256).
  • Multi-factor authentication: add a second layer of sign-in protection with an authenticator app or SMS.
  • SOC 2 aligned controls: our security program is documented, tested, and designed to align with core SOC 2 control areas.
  • No linked accounts required: you can use ProjectionLab without connecting a bank or brokerage account.

ProjectionLab does not ask for sensitive information like account numbers, and you don’t even need to use your real name. It holds the numbers you plan with, not the keys to your accounts. What you share is up to you.

Infrastructure

ProjectionLab runs on Google Cloud Platform and Google Firebase. Application data is stored in Google Cloud Firestore, and the app is served globally through Firebase Hosting. We run automated daily backups and regularly test our restore process.

ProjectionLab is built on Google Cloud infrastructure covered by certifications including SOC 1/2/3 and ISO 27001, which helps provide a strong security foundation for our platform. You can review Google Cloud’s Trust Center, compliance offerings, Firebase security documentation, and encryption documentation. These certifications apply to Google Cloud’s infrastructure and controls rather than ProjectionLab itself.

Encryption

Connections to ProjectionLab use HTTPS with TLS, so data is encrypted in transit between your browser and our servers. Application data stored in Cloud Firestore is encrypted at rest using Google Cloud’s AES-256 encryption.

Authentication & Access

  • Sign-in: We use Firebase Authentication with support for email/password and Google sign-in.
  • Multi-Factor Authentication: You can add MFA to your account using an authenticator app (TOTP) or SMS.
  • Data Isolation: Your data is walled off from other accounts, and that boundary is enforced at the database layer.
  • Internal Access: Administrative access follows least privilege. It is role-based, limited to the small number of people who need it, and protected by MFA.

Privacy & Data Handling

We never sell your data. We do not share your planning data with third parties for advertising or marketing.

You can export your planning data for portability and delete your account and planning data from within the app. We use a small number of third-party service providers to operate ProjectionLab, including Google Cloud for hosting and Paddle for payment processing. For full details, see our Privacy Policy.

Payments

Subscriptions are processed by Paddle, our merchant of record. You enter payment details directly with Paddle at checkout: your card number never touches ProjectionLab’s systems, and we do not store your credit card number or other payment-card details. Paddle handles payment card security, including PCI DSS compliance, and you can learn more at the Paddle Trust Center.

Account Deletion

You can delete your account from within the app. This removes your account and planning data from our active systems, and backup copies expire automatically on a fixed schedule. We may retain limited records where required for billing, tax, or legal purposes.

Security Incidents

We maintain a documented process for responding to security incidents. If we ever discover unauthorized access to personal information on our systems, we will investigate, respond, and notify affected users as required by applicable law.

Vulnerability Reporting

We welcome good-faith reports that help keep ProjectionLab secure. If you believe you’ve found a security issue, email security@projectionlab.com with enough detail for us to investigate.

We do not run a bug bounty program, and this page does not authorize testing against our systems.

For Advisors and Compliance Teams

ProjectionLab operates a documented and tested security program designed to align with core SOC 2 control areas, including access management, change management, monitoring, incident response, vendor oversight, and business continuity.

If your review requires something not covered on this page, contact security@projectionlab.com.

Contact

This page reflects current practices and may be updated from time to time.

Disclaimer: The content, tools, and resources on ProjectionLab.com are intended solely for informational and educational purposes and should not be construed as professional financial or investment advice. Our materials are designed to provide general guidance and are based on the input and data provided by users. ProjectionLab makes no guarantee of the accuracy, completeness, or applicability of this content to individual circumstances. Effective financial planning and investment involve comprehensive consideration of a wide array of personal financial factors. The tools and resources available on ProjectionLab are aimed at helping users develop an understanding of their financial trajectory. However, they should not be solely relied upon for creating a complete financial plan. We strongly recommend consulting a financial services professional who can provide personalized advice based on your unique financial situation before making any significant financial decisions. While we endeavor to keep the information on ProjectionLab current and accurate, the content may differ from that found on other financial institutions, service providers, or specific product sites. All content and tools on ProjectionLab are provided without any guarantees or warranties of any kind.