Live payments — real cards will be charged. Test cards will be declined.

Trust & Operations

Where your data lives, how it is secured, how we recover from incidents, and how to reach us.

Security findings

No open findings

Data region

EU (Lovable Cloud / Supabase)

Backup retention

30 days

Platform version

1.0.0

Security

  • Row-level security is enforced on every tenant table. College staff can only access their own college's data.
  • Multi-factor authentication is required for platform administrators. Super admins use TOTP; college staff can use email OTP.
  • Automated security scans run across the database, code, dependencies, and connectors. The last scan found 0 open findings.
  • All payments are handled by Stripe; card data never touches our servers.

Backups & disaster recovery

  • Automated full-platform snapshots are taken daily and stored in encrypted object storage.
  • Snapshot retention is configured for 30 days. Encrypted off-site copies are retained beyond that window.
  • Restore drills are performed periodically to verify that snapshots can be restored to a fresh environment.
  • A documented outage runbook is available to platform staff, with escalation paths and rollback procedures.

Data residency & uptime

The platform is hosted on Lovable Cloud. The database and primary storage are located in EU (Lovable Cloud / Supabase). Public-facing pages are served from an edge network for performance and resilience.

SSO-ready
TLS 1.2+
Encrypted at rest
Automated patching

Support & contacts

Critical response target: 1 hour

Standard response target: 1 business day

Support contacts are being configured.

Platform-level escalation

If the issue is with the underlying hosting platform (Lovable) rather than this service, it is escalated by the platform owner through these channels.

Priority support availability depends on the platform subscription tier held by the platform owner (offered on Business and Enterprise plans).

Last reviewed not yet.Return to the home page