Their trust is your business.
Your customers hand you their address, their gate code, and a five-figure check. Projlog holds some of that on your behalf. This page says exactly how we treat it, in the same plain words we use everywhere else.
Last reviewed August 2026. When something on this page changes, we say so in the changelog, not in a quiet edit.
- Encrypted in transit and at rest, no exceptions.
- Card numbers never touch us. Payments run on a PCI-DSS Level 1 processor.
- Every company's data is isolated per tenant.
- Export everything, any time. It's your book of business, not ours.
- We don't sell data, run ads, or mine your customer list.
What we hold. What we never touch.
Most security pages list acronyms. This one lists the actual data, because that's what your customer would ask about.
Boring on purpose.
TLS 1.2+ for everything in transit, AES-256 at rest. Photos, messages, documents, backups, all of it. No "encryption available on the enterprise plan."
Every company's data carries its tenant ID at the row level, checked on every query. Your competitor on the same plan can't see your customer list under any bug we know how to write.
Office, crew lead, crew. Crew members see the job, not the customer thread. You set it once in Settings and the API enforces it everywhere, including exports.
Checkout fields are served by our PCI-DSS Level 1 payment processor and post directly to them. We store a token and a receipt. A breach of Projlog cannot leak a card number we never had.
Managed daily backups of the database, encrypted at rest, with a documented restore procedure we have exercised. We are still building independent backup of uploaded files and a recurring restore drill, and we would rather say that than imply a guarantee we cannot yet meet.
Sign-ins, exports, permission changes, and deletions are logged with who and when. Admins can read the log; nobody can quietly edit it.
Magic-link sign-in means no password database to crack. Customer portals are scoped to one job. The crew app can post notes and photos, not read your books.
We do not hold a SOC 2 report and have not had a third-party penetration test. We are not going to print a badge we did not earn. What we do run: dependency patching on a weekly cadence, automated security checks on every change, and an internal production-readiness review whose findings are tracked to closure. If a SOC 2 report is a hard requirement for you, ask, and we will tell you exactly where we are.
Tell us. We'll thank you, not sue you.
If you find a vulnerability, report it and give us a reasonable window to fix it. Good-faith research within the rules gets safe harbor and a public thank-you, never legal threats.
security@projlog.appThe door isn't locked.
Export your customers, jobs, messages, photos, and money records in open formats from Settings, no phone call, no retention offer. Cancel, and we delete your data from production within 30 days and from backups within 60.
The fine print, in the privacy policy →