Trust & Security
This page is maintained by the Ethos OS team to answer common security and privacy questions about how the platform handles customer information.
This page is editable app-owner content. It describes current practices and enabled platform capabilities, and is not an independent certification or third-party audit.
Access & Authentication
Sign-in is handled by our managed authentication provider. Sessions use short-lived tokens, and access to internal tools is gated by role-based permissions enforced both in the UI and at the database layer.
Data Protection
Customer data is held in a managed Postgres database with row-level security policies that scope each query to the signed-in user's role and ownership. Connections are encrypted in transit.
Platform & Hosting
Ethos OS is built on the Lovable Cloud platform. Hosting, database, edge functions, and storage are provided by Lovable's underlying infrastructure providers. This page describes app-level practices, not an independent audit.
Subprocessors & Integrations
We integrate with third-party services that customers opt into (for example email, calendar, and loan-origination systems). Credentials for those integrations are scoped per user and revocable from the app.
Retention & Deletion
Account owners can request deletion of their data. Operational logs are retained for a limited period for security, audit, and debugging purposes, then aged out.
Security Contact
To report a vulnerability or ask a security question, contact the Ethos OS team through your account representative or the in-app support channel.
Shared responsibility
Security is a shared responsibility. The Lovable Cloud platform provides the underlying infrastructure controls; the Ethos OS team configures and operates the application on top; and customers are responsible for safeguarding their own account credentials and the data they choose to enter.
