Security
What we verified. What we rely on. What is not in place yet.
This page only states what we tested ourselves, what a named provider is responsible for, and what we do not have. Saloa labels what is fact, inference, assumption or unknown. Where evidence is missing, it says so. We apply the same rule here.
01
Verified by us
On 2 October 2026 we ran the tests below ourselves, against our production environment. Every control below was tested. These are our own tests, not an independent audit.
| Control | Coverage | Result | What it means |
|---|---|---|---|
| Database access rules | Every table | Enforced | Every table in the application database has row-level access rules switched on. There is no table that can be read without them. |
| Separation between customers | All customer, project and payment data | Enforced in the database | Rows are only visible to their owner. Signed-in attempts to read, change, delete or impersonate another account were all blocked. |
| Access without signing in | All private data | Refused | Reads, inserts and updates on private data without a signed-in account were all refused. |
| Payments and credits | Every session start | Locked per transaction | A credit is claimed inside one locked database transaction, so simultaneous requests can never spend the same credit twice. |
| Internal functions | All internal database functions | Not callable from outside | Internal functions refuse callers without the right role. |
| Research network perimeter | Every outbound research request | Filtered | Requests to local, private-network and cloud-metadata addresses, or addresses with embedded credentials, are refused. Only public addresses pass. |
| AI input hygiene | Every text sent to AI models | Sanitised | Control characters, structural tags, known instruction-override patterns and over-long input are removed or truncated before analysis. |
| Abuse limits | Costly and sensitive actions | Rate limited | Requests above the limit are blocked automatically. |
| Secrets | All code sent to browsers | 0 secrets found | Service keys, webhook secrets and API keys live only on the server, never in browser code or public files. |
Date of run: 2 October 2026. At the last check on 5 October 2026, row-level security was on for all 67 tables in the application database.
02
Provided by our infrastructure partners
- Data is encrypted in transit and at rest by our infrastructure providers.
- The underlying data storage and hosting environments are operated by providers that publish SOC 2 Type II reports and ISO 27001 certification. These certifications belong to those providers, not to Saloa. Each provider's own trust page is linked in the table below.
- Our database runs with Supabase on Amazon Web Services in Frankfurt (eu-central-1).
03
Not yet in place
- No SOC 2 or ISO 27001 for Saloa itself. Saloa has not been audited as a company.
- No independent penetration test. The register above is our own testing.
- Not yet published here: results for data deletion, data export, AI context isolation between accounts and file handling. We will add them only after they are tested.
- Deleting your login account currently goes through support at studio@getsaloa.com.
04
Who receives data
Every outside party our application sends data to, read from our code and configuration. We found no third-party analytics or error-logging service in the application. All processing regions are in the EU.
| Party | Purpose | Data received | Infrastructure used | Region | Their privacy / trust page |
|---|---|---|---|---|---|
| Lovable | Application hosting, server functions, AI and connector gateway, transactional email | All application traffic; email address for account emails | Google Cloud, Cloudflare | EU | lovable.dev/security → |
| Supabase | Database, sign-in and access rules | Account and business data you store in Saloa | Amazon Web Services | EU | supabase.com/security → |
| Stripe | Payments | Payment and billing details; card data is entered with Stripe | Operated by Stripe | EU | stripe.com/privacy → |
| OpenAI (via Lovable AI Gateway) | Analysis, interviews and written output | The text of your interview, questions and research material sent for analysis | Operated by OpenAI | EU | openai.com/enterprise-privacy → |
| Google Gemini (via Lovable AI Gateway) | Analysis for part of the reasoning steps | The text sent for analysis in those steps | Google Cloud | EU | ai.google.dev/gemini-api/terms → |
| Firecrawl | Reading public web pages for company research | Company names, domains and public URLs submitted for research | Operated by Firecrawl | EU | firecrawl.dev/privacy-policy → |