Security Schedule
Last updated August 21, 2026
This schedule summarizes the safeguards used for Ecosystem Navigator. It describes current practices and does not claim a certification or independent audit that The Groundbreakers Inc. has not obtained.
Infrastructure and encryption
The Service runs on Google Cloud and Firebase managed infrastructure. Network traffic uses HTTPS/TLS. Managed Google Cloud and Firebase services encrypt stored data at rest. Payment card data is collected and processed by Stripe rather than stored by Groundbreakers.
Identity and access
Firebase Authentication manages user identity. Application rules and server-side authorization separate user, organization, participant, and administrator access. Administrative functions are restricted to authorized accounts. Service credentials and API secrets are kept in managed deployment secrets and are not committed to source control.
Application and data controls
The application validates protected API requests, limits client access to server-only collections, minimizes data sent to research providers, restricts benchmark source records, and applies aggregation or minimum cohort controls to user-facing benchmarks. Public sharing is controlled by explicit share features and revocable links.
Development and operations
Changes are maintained in version control and checked through available type, build, integrity, and targeted test workflows. Operational event and error records support reliability and incident investigation. Provider and application configuration is reviewed as the Service changes.
Incident response and continuity
Groundbreakers maintains procedures to receive, assess, contain, document, and escalate privacy and security incidents. Where required, it reports to regulators, notifies affected people or customers, and preserves breach records. Service continuity relies in part on managed cloud resilience and provider backup systems; no recovery time or uninterrupted availability is guaranteed unless agreed in writing.
Customer responsibilities
Customers must protect credentials, promptly remove access that is no longer needed, configure organizations and sharing appropriately, obtain authority for uploaded data and invitations, verify recipients, and notify us of suspected compromise. Security concerns may be reported to ibarker@thegroundbreakers.net.