Skip to content

    SECURITY / OPERATIONS

    Security questions deserve project-specific answers.

    Where is the data stored? How often is it backed up? What happens after an incident? We document the actual setup for each project rather than claiming every client platform has the same hosting and recovery commitments.

    01

    Hosting and location

    The provider and region depend on the project’s architecture and chosen services. We confirm the actual hosting region, subprocessors and any transfers in the project agreement or data-processing documentation. “Hosted in Europe” should not be assumed without checking every data store and integration.

    02

    Backups and recovery

    We agree which databases and files are backed up, their frequency and retention, who can restore them and how recovery is tested. A provider offering backups does not by itself establish a particular recovery time or a backup policy for your application.

    03

    Access and application security

    We scope user permissions, authentication, encryption in transit, updates and monitoring to the application. We can discuss what is implemented and what remains to be addressed before launch. No platform label replaces an application-specific security review.

    04

    What provider certificates mean

    Lovable describes SOC 2 Type II and ISO 27001:2022 for the documented scope of its Enterprise offering, and AIUC-1 for its AI coding agent. These are Lovable-level claims, not certifications of Axiom or of your application. We provide current provider documentation when relevant and confirm whether the selected services and plan are in scope.

    05

    If the provider changes

    Data portability, source-code rights, documentation and replacement hosting are separate matters. We can scope a continuity plan and, if required, a source-code buyout; neither is included automatically with a standard subscription.

    The English terms govern. Confirm project-specific commitments in writing.