Trust Center
Security & Trust
This page describes how Projection-X handles your data and content — concretely and verifiably, without marketing phrases. Everything here reflects the platform's actual technical state.
Encryption & infrastructure
- Every connection runs over HTTPS — enforced via HSTS (2 years, including subdomains).
- Operated in the EU: servers in Dublin, database in the EU (Ireland).
- Every response carries a full set of security headers: Content-Security-Policy, clickjacking protection, nosniff, restrictive referrer and permissions policies (location switched off; camera and microphone only for the coaching video room on this site itself, never for third parties).
Payments
- All payments run exclusively through Stripe, a PCI-DSS-certified payment provider.
- Full card details never reach our servers.
- Prices and discounts are set and validated server-side; payment confirmations from Stripe are cryptographically signature-verified.
Account protection
- Registration with email verification: the code from the welcome mail (or its link) activates the account.
- An email-code second factor is available for every account — mandatory for admin access, plus an additional admin gate with PIN and security questions (30-day rotation).
- Security codes and keys are never stored in plain text: 2FA codes (valid 10 minutes, 5 attempts), session tokens and device identifiers are stored as hashes only.
Your data (GDPR)
- Data minimization: an account needs only email and password — name, picture and location are optional.
- No analytics, tracking or advertising services. Not a single marketing cookie. Fonts are self-hosted — no connection to Google Fonts.
- External videos and embedded posts (YouTube, Vimeo, Mux, Instagram) load only once you allow the provider — in the cookie dialog or at the placeholder; a click on “Play” does not replace this permission. The dialog has equal buttons to reject and accept and can be changed at any time via “Cookie settings”.
- Fixed deletion periods: security logs after 180 days, license and download logs after 90 days, consumed sign-in codes after 30 days — automatically.
- Newsletter only with double opt-in and one-click unsubscribe in every mail.
- Your rights under Art. 15–21 GDPR (access, rectification, erasure and more) are described in the privacy policy — one email is enough.
Content & downloads
- Purchased files live in private storage that is never publicly reachable — delivery happens only via short-lived, single-use, signed links after a purchase check.
- Delivery of download files runs through a built-in malware gate — files flagged as harmful are never delivered.
- Licenses are limited server-side to at most 2 devices — you manage your devices yourself in your account.
Architecture
- Deny by default: every page is protected until it is explicitly made public.
- The database is double-locked: row-level security on all tables plus a full privilege revoke for the public API roles.
- Database access runs exclusively through bound parameters — SQL injection is structurally impossible.
Tested, not claimed
Two audits, both documented. The internal white-box audit of 18 August 2026 tested the platform against 131 documented attack scenarios and closed 17 findings. On 12 September 2026 a full compliance and security audit followed, covering 298 checkpoints, with 107 confirmed findings. How many of those are closed today we deliberately do not state here as a fixed number: a review on 18 September 2026 was explicitly tasked with refuting our own remediation claims, and it disputed part of them. The current state of that work is on our audit and AI transparency page — with figures, because that is where they are allowed to move. That we write this down is the point: a platform without findings is one that was never examined.
Audit status and ongoing remediation →Found something?
If you spot a security issue, please report it to us directly — we respond quickly and take every report seriously.
As of: 18 September 2026 · Audited 12 September 2026 · Re-reviewed 18 September 2026 · The figures under “Tested, not claimed” appear as such in the reports named there.