Trust & Operations
Where your data lives, how it is secured, how we recover from incidents, and how to reach us.
Security findings
No open findings
Data region
EU (Lovable Cloud / Supabase)
Backup retention
30 days
Platform version
1.0.0
Security
- Row-level security is enforced on every tenant table. College staff can only access their own college's data.
- Multi-factor authentication is required for platform administrators. Super admins use TOTP; college staff can use email OTP.
- Automated security scans run across the database, code, dependencies, and connectors. The last scan found 0 open findings.
- All payments are handled by Stripe; card data never touches our servers.
Backups & disaster recovery
- Automated full-platform snapshots are taken daily and stored in encrypted object storage.
- Snapshot retention is configured for 30 days. Encrypted off-site copies are retained beyond that window.
- Restore drills are performed periodically to verify that snapshots can be restored to a fresh environment.
- A documented outage runbook is available to platform staff, with escalation paths and rollback procedures.
Data residency & uptime
The platform is hosted on Lovable Cloud. The database and primary storage are located in EU (Lovable Cloud / Supabase). Public-facing pages are served from an edge network for performance and resilience.
Support & contacts
Critical response target: 1 hour
Standard response target: 1 business day
Support contacts are being configured.
Platform-level escalation
If the issue is with the underlying hosting platform (Lovable) rather than this service, it is escalated by the platform owner through these channels.
Priority support availability depends on the platform subscription tier held by the platform owner (offered on Business and Enterprise plans).