Skip to main content
Security & trust

Their trust is your business.

Your customers hand you their address, their gate code, and a five-figure check. Projlog holds some of that on your behalf. This page says exactly how we treat it, in the same plain words we use everywhere else.

Last reviewed June 2026. When something on this page changes, we say so in the changelog, not in a quiet edit.

The short version
  • Encrypted in transit and at rest, no exceptions.
  • Card numbers never touch us. Payments run on a PCI-DSS Level 1 processor.
  • Every company's data is isolated per tenant.
  • Export everything, any time. It's your book of business, not ours.
  • We don't sell data, run ads, or mine your customer list.
SOC 2 · Type II
Plain-words data inventory

What we hold. What we never touch.

Most security pages list acronyms. This one lists the actual data, because that's what your customer would ask about.

We hold, encrypted
Names, addresses, phone numbersYour customer list and job sites. Visible only to your team, by the roles you set.
Messages and crew notesThe project thread, internal notes included. Internal stays internal, that's enforced, not promised.
Photos and documentsJob photos, estimates, signed contracts. Stored privately, shared only through links you create.
Invoice and payment recordsAmounts, dates, and status, so your books make sense. Records of payments, never the instruments.
We never touch
Card and bank numbersThey go straight from your customer's device to the payment processor. Our servers never see a digit.
Social security numbersNothing in Projlog asks for one, on purpose. There's no field to leak.
Your customers, as a marketNo ads, no upsells to your customers, no "anonymized insights" sold sideways. They're yours.
Precise location of your crew"On site" is a button a human presses, not a tracker. No GPS tracking.
How it's kept

Boring on purpose.

01Encryption everywhere

TLS 1.2+ for everything in transit, AES-256 at rest. Photos, messages, documents, backups, all of it. No "encryption available on the enterprise plan."

02Tenant isolation

Every company's data carries its tenant ID at the row level, checked on every query. Your competitor on the same plan can't see your customer list under any bug we know how to write.

03Roles that match a real shop

Office, crew lead, crew. Crew members see the job, not the customer thread. You set it once in Settings and the API enforces it everywhere, including exports.

04Payments at arm's length

Checkout fields are served by our PCI-DSS Level 1 payment processor and post directly to them. We store a token and a receipt. A breach of Projlog cannot leak a card number we never had.

05Backups you could actually use

Encrypted backups every hour, tested restores every month, stored in a second region. Recovery time measured in hours, not "we'll get back to you."

06Audit trail

Sign-ins, exports, permission changes, and deletions are logged with who and when. Admins can read the log; nobody can quietly edit it.

07Small attack surface

Magic-link sign-in means no password database to crack. Customer portals are scoped to one job. The crew app can post notes and photos, not read your books.

08Independent checks

SOC 2 Type II audit annually, third-party penetration test every year, dependencies patched on a weekly cadence. The SOC 2 report is available under NDA, ask.

Found something?

Tell us. We'll thank you, not sue you.

If you find a vulnerability, report it and give us a reasonable window to fix it. Good-faith research within the rules gets safe harbor and a public thank-you, never legal threats.

security@projlog.app
Leaving?

The door isn't locked.

Export your customers, jobs, messages, photos, and money records in open formats from Settings, no phone call, no retention offer. Cancel, and we delete your data on a 30-day clock, backups included on the next cycle.

The fine print, in the privacy policy →
Security & trust

Ask us the hard questions on a live demo.