Security

What we verified. What we rely on. What is not in place yet.

This page only states what we tested ourselves, what a named provider is responsible for, and what we do not have. Saloa labels what is fact, inference, assumption or unknown. Where evidence is missing, it says so. We apply the same rule here.

01

Verified by us

On 2 October 2026 we ran the tests below ourselves, against our production environment. Every control below was tested. These are our own tests, not an independent audit.

ControlCoverageResultWhat it means
Database access rulesEvery tableEnforcedEvery table in the application database has row-level access rules switched on. There is no table that can be read without them.
Separation between customersAll customer, project and payment dataEnforced in the databaseRows are only visible to their owner. Signed-in attempts to read, change, delete or impersonate another account were all blocked.
Access without signing inAll private dataRefusedReads, inserts and updates on private data without a signed-in account were all refused.
Payments and creditsEvery session startLocked per transactionA credit is claimed inside one locked database transaction, so simultaneous requests can never spend the same credit twice.
Internal functionsAll internal database functionsNot callable from outsideInternal functions refuse callers without the right role.
Research network perimeterEvery outbound research requestFilteredRequests to local, private-network and cloud-metadata addresses, or addresses with embedded credentials, are refused. Only public addresses pass.
AI input hygieneEvery text sent to AI modelsSanitisedControl characters, structural tags, known instruction-override patterns and over-long input are removed or truncated before analysis.
Abuse limitsCostly and sensitive actionsRate limitedRequests above the limit are blocked automatically.
SecretsAll code sent to browsers0 secrets foundService keys, webhook secrets and API keys live only on the server, never in browser code or public files.

Date of run: 2 October 2026. At the last check on 5 October 2026, row-level security was on for all 67 tables in the application database.

02

Provided by our infrastructure partners

  • Data is encrypted in transit and at rest by our infrastructure providers.
  • The underlying data storage and hosting environments are operated by providers that publish SOC 2 Type II reports and ISO 27001 certification. These certifications belong to those providers, not to Saloa. Each provider's own trust page is linked in the table below.
  • Our database runs with Supabase on Amazon Web Services in Frankfurt (eu-central-1).

03

Not yet in place

  • No SOC 2 or ISO 27001 for Saloa itself. Saloa has not been audited as a company.
  • No independent penetration test. The register above is our own testing.
  • Not yet published here: results for data deletion, data export, AI context isolation between accounts and file handling. We will add them only after they are tested.
  • Deleting your login account currently goes through support at studio@getsaloa.com.

04

Who receives data

Every outside party our application sends data to, read from our code and configuration. We found no third-party analytics or error-logging service in the application. All processing regions are in the EU.

Company names and URLs you submit for research are sent to our research and AI providers.
PartyPurposeData receivedInfrastructure usedRegionTheir privacy / trust page
LovableApplication hosting, server functions, AI and connector gateway, transactional emailAll application traffic; email address for account emailsGoogle Cloud, CloudflareEUlovable.dev/security →
SupabaseDatabase, sign-in and access rulesAccount and business data you store in SaloaAmazon Web ServicesEUsupabase.com/security →
StripePaymentsPayment and billing details; card data is entered with StripeOperated by StripeEUstripe.com/privacy →
OpenAI (via Lovable AI Gateway)Analysis, interviews and written outputThe text of your interview, questions and research material sent for analysisOperated by OpenAIEUopenai.com/enterprise-privacy →
Google Gemini (via Lovable AI Gateway)Analysis for part of the reasoning stepsThe text sent for analysis in those stepsGoogle CloudEUai.google.dev/gemini-api/terms →
FirecrawlReading public web pages for company researchCompany names, domains and public URLs submitted for researchOperated by FirecrawlEUfirecrawl.dev/privacy-policy →