Trust & Security

Security at Plarelo.

A relocation involves some of your most sensitive information, passports, family details, finances. Protecting it is foundational to how we build Plarelo. Here is how we do it.

SOC 2-compliant infrastructure

Plarelo runs entirely on managed cloud platforms that maintain SOC 2 Type II compliance. Your data is encrypted in transit (TLS) and at rest, on infrastructure with independently audited security controls.

Your data stays yours

Access is enforced in the database itself with row-level security, not just in the app. Every request is authorized against your identity at the data layer, so one account can only ever reach its own projects and information.

Secure authentication

Accounts use email-verified sign-up and a modern PKCE authentication flow. Passwords are hashed by our authentication provider and are never stored or visible to us in plain text.

Continuous security testing

Every change to Plarelo passes through automated security checks before it ships, dependency vulnerability scanning, secret detection, and database security linting, so known issues are caught and patched promptly.

Secure engineering by default

We ship strict security headers (Content-Security-Policy, HSTS and more), guard against open redirects, rate-limit sensitive actions, and keep all secret keys isolated to the server, never exposed to your browser.

Only what we need

We collect the minimum information required to build your relocation plan and handle it in line with the GDPR. See our Privacy Policy for the full detail on what we store and why.

Have a security question?

Whether you want to understand our practices in more detail or report a potential security concern, we want to hear from you and aim to respond quickly.

Contact us

Last reviewed: August 2026