Security

How Parallel Worlds protects accounts, operational data, and platform infrastructure across Earth, Quantum, Angel, and related products. Last updated August 19, 2026.

Data Protection

Traffic to the Services is encrypted in transit with TLS. Sensitive records are stored with our cloud and authentication providers under access controls. No platform can promise perfect security; we design to reduce risk and contain incidents.

  • TLS for data in transit
  • Hosted databases and object storage with provider encryption at rest
  • Least-privilege credentials for production services

Account security

Authentication is handled by our identity provider. You can enable an authenticator-app second factor in Account Settings. If MFA is enabled, a password alone is not enough to use the product — you must complete the authenticator challenge.

  • Optional (strongly recommended) TOTP multi-factor authentication
  • Session cookies managed by the auth provider — do not share devices
  • Disabling MFA requires a current authenticator code

Infrastructure

Application hosting, authentication, and data stores run on established cloud platforms. Secrets for maps, billing, and AI stay on the server. Public clients only receive what they need to operate.

  • Server-only secrets for maps, feeds, and AI providers
  • Signed webhooks for billing events where supported
  • Regular dependency and platform updates

Privacy & compliance

Our practices are described in the Privacy Policy. We aim to meet applicable privacy laws, including California consumer rights and GDPR where they apply. This page is an overview, not a certification.

  • Access, deletion, and correction requests via admin@parallelworlds.us
  • Cookie and sharing choices at Cookies and Do Not Sell

Application & API security

APIs and map workspaces use authenticated sessions. Incomplete MFA (password without the second factor) is rejected for protected pages and APIs.

  • Server-side session verification
  • MFA assurance checks before entering the product
  • Role-based access for administrative tools

Your responsibilities

Use a unique password, enable MFA, keep your authenticator device safe, and sign out on shared computers. Report suspected account takeover immediately.

Report security issues

If you discover a vulnerability, email us. Please do not publicly disclose it until we have had a reasonable chance to fix it. Do not access other users' data or disrupt the service while testing.

Security email

admin@parallelworlds.us

Response

We review reports as quickly as we reasonably can during business hours.