Skip to main content
WheelsUp
Trust

Security

Last updated: 2026-08-23
WheelsUp is operated by Military Wheels Up LLC, a Florida limited liability company (document no. L26000398989).
How we protect your account and your plan data. We store military-community PII, so we treat security as a first-class part of the product — not an afterthought.
On this page
Encryption Passwords Two-factor authentication Account isolation Payments Abuse protection Your data, your control Backups Third-party code Data minimization Report a vulnerability

Encryption in transit & at rest

In plain terms: your connection is HTTPS, and the database file itself is encrypted with a key we hold.

All traffic to WheelsUp is served over HTTPS/TLS. Your account and plan data are encrypted at rest in two independent layers. The hosting platform encrypts the storage volume it gives us, as it does for every customer. On top of that, we encrypt the database file itself — whole-file page encryption, under a key we hold separately from that platform’s own storage encryption. A copy of the volume is therefore not a copy of your data.

To be precise about what that does not mean: the application runs on that platform and must hold the key in memory to answer your requests, so this protects data at rest. It is not a claim that our hosting provider is technically unable to reach data while the service is running. Our off-host backups are sealed again separately — see Backups.

Password handling

In plain terms: we never store your password — only a salted, hashed version we can't reverse.

Passwords are hashed server-side with PBKDF2-HMAC-SHA256 and a unique per-user salt before storage. We never store or log plaintext passwords, and we cannot see them. Password changes and resets invalidate existing sessions on your other devices.

When you choose a password we check its strength and screen it against known public data breaches, so a password that attackers already have on a list can't be used here. That check never transmits your password — we send only the first five characters of its hash and compare the results locally. See Service providers in our Privacy Policy for details.

Two-factor authentication

In plain terms: you can require a code from your phone at sign-in, so your password alone isn't enough to get into your account.

You can turn on two-factor authentication from your account settings. It uses a standard authenticator app (TOTP, RFC 6238) — Google Authenticator, 1Password, Authy, or your password manager — and we never send authentication codes by SMS, which is the weakest of the common methods.

The secret your app is set up with is encrypted before it is stored, under a key held separately from the database, so a copy of the database alone cannot be used to generate your codes. Each code can be used once: a code that has already signed you in is refused for the rest of the period it would otherwise be valid.

Turning two-factor authentication on gives you ten single-use recovery codes for the day you lose your phone. They are shown once and stored only as hashes, so we cannot recover them for you — keep them somewhere safe. Turning the feature off again requires both your password and a current code, and resetting your password does not bypass it.

Account isolation

In plain terms: your plan is tied to your account — one user can't read another's data.

Every data request is scoped to your authenticated account at the query layer, so one user can never read or modify another's data. Sessions are signed and can be revoked.

Payments

In plain terms: Stripe handles your card — we never see or store full card numbers.

Payments are processed by Stripe. We never see or store your full card number. Your access level is set only by Stripe's signature-verified confirmation — it can't be forged from the browser.

Abuse & bot protection

In plain terms: rate limits, bot checks, and email verification keep accounts and the service safe.
  • Rate limiting on sign-up, login, and password-reset to slow brute-force and abuse.
  • A bot challenge (CAPTCHA) on account creation and password reset.
  • Email verification required before an account can be used.
  • Administrative actions on accounts are recorded in an audit log.

Your data, your control

You can export your data or delete your account at any time from your account settings — no support ticket, no waiting on us.

The export is a single JSON file containing your account record, your complete plan data, your billing record, and the analytics and error events still linked to your account. Deleting removes your account, plan data, and billing record from the live database immediately; encrypted backups still hold a copy for up to 30 days before they age out (see Backups). See the Privacy Policy for the full picture.

Backups

In plain terms: we take a backup every day and keep 30 days of them, stored encrypted at rest, so a hardware failure can't lose your plan.

A consistent snapshot of the database is taken daily, compressed, and stored in Cloudflare R2 — deliberately a different provider from the one hosting the app, so a single provider's bad day can't take both the service and its backups. Cloudflare encrypts every object in R2 at rest with AES-256, automatically. We keep about 30 days of snapshots and automatically delete older ones.

We encrypt each snapshot on our own server, before it leaves it. The backup is compressed and then encrypted with AES-256-GCM under a key held only by us — never by the companies that move or store the file. Only then does it travel.

That matters because of where it travels. The job that moves a backup off the host runs on GitHub's build infrastructure — a new virtual machine for each run — so a copy of the encrypted backup passes through it. Because we seal the file first, that machine never sees a readable copy of the database and cannot open what it carries. Both legs of the transfer are also encrypted in transit (SSH off the host, HTTPS up to R2), and Cloudflare encrypts every object in R2 at rest on top of our own encryption. Backups are used only to restore the service — never to look up an individual account. Because a snapshot is a point-in-time copy, data from a deleted account persists in backups until those snapshots age out, up to 30 days.

Third-party code

In plain terms: almost nothing loads from anyone else's servers — including our fonts.

The app runs no third-party analytics, advertising, or tracking scripts. Our webfonts are served from our own origin rather than a font CDN, so opening a page doesn't disclose your IP address to a third party. The only external code we load is Cloudflare's anti-bot widget on sign-up and password reset, and payment pages hosted by Stripe — both of which have to run on their own infrastructure to do their job.

Data minimization

In plain terms: we deliberately don't collect sensitive government identifiers.

We don't ask for your SSN, DoD login credentials, or other sensitive government identifiers, and you shouldn't enter them. We collect only what's needed to run your plan.

Report a vulnerability

In plain terms: found a security issue? Tell us — we want to fix it.

Responsible disclosure is welcome. If you believe you've found a security vulnerability, contact us → with the details and please give us a reasonable chance to fix it before public disclosure.

Veterans Crisis Line — free, confidential support, 24/7. You do not need to be enrolled in VA care.

Dial 988, then press 1 · Text 838255 · Chat online

Overseas: dial DSN 988 on base, or find your region’s number.

WheelsUp

Plan your military transition and retirement with confidence — milestones, leave, and pay, back-planned from your dates.

Product

Features Advanced tools Pricing FAQ Transition guides For organizations

Support

Get help Send feedback Request a feature Contact support System status

Legal

Privacy Policy Consumer Health Data Terms of Service Acceptable Use Sources & corrections Security Accessibility
© WheelsUp · Military Transition & Retirement Planner
Estimate only — not official military, financial, or legal advice. Verify with finance, MPF/MPS, and the VA.