Security
Last reviewed: August 25, 2026
UTM Assistant is built entirely on Google Cloud Platform (GCP) — no self-managed servers, no mixed infrastructure. Every part of the platform inherits GCP's security and reliability foundation, on top of what we build ourselves.
Infrastructure
Hosting, authentication, data storage, and Inflight's correction service all run on Google Cloud Platform and Firebase. Because there's no self-managed hardware anywhere in the stack, the platform inherits GCP's physical security, network security, and operational practices — independently audited by Google against standards including ISO 27001, SOC 2, and SOC 3. (These certifications cover Google Cloud's infrastructure; see Google Cloud's own compliance documentation for scope and detail.)
Environment separation
We run three fully separate Firebase/GCP projects — development, staging, and production. Local development and testing never touch production data.
Authentication
Account access is handled by Firebase Authentication with Identity Platform, which supports multi-factor authentication and audit logging.
Encryption
Data is encrypted in transit (TLS) and at rest, using GCP's default encryption.
Audit trail
Every correction Inflight makes is logged with the before/after value, the rule that triggered it, and the actor — so you can always see exactly what changed and why.
Payments
Billing is handled by Stripe. We never see or store your full card details.
Reporting a concern
If you've found a security issue, contact us at legal@utm-assistant.ai.