Trust & Security
This page is maintained by the StrategyHub™ team to answer common security and privacy questions about StrategyHub™. It describes controls and practices currently enabled in the product. It is not an independent certification or audit.
Procurement and information security reviewers: see the detailed security & U.S. data residency overview, HECVAT-Lite answers, incident response plan, and subprocessor list.
Access & authentication
Sign-in supports email + password and Google sign-in. Optional time-based one-time password (TOTP) multi-factor authentication is available to every user.
Organization admins can require MFA for all members of their workspace and restrict access to specific IP addresses or CIDR ranges. Both controls are enforced server-side on every authenticated request.
Role-based access (admin / member) is enforced in the database, not just in the UI.
Data isolation
Each organization is a separate tenant. Database row-level security policies scope every read and write to the user's organization memberships — data does not cross between tenants.
Sensitive credentials such as webhook secrets, integration tokens, embed tokens, and email tokens are not readable through the public data API; only server-side code with elevated privileges can access them.
Platform, hosting & U.S. data residency
StrategyHub™ runs on the Lovable Cloud platform, which provides managed Postgres, authentication, file storage, and serverless functions. Data is encrypted in transit (TLS) and at rest by the underlying managed services.
The production database and file storage are hosted on Amazon Web Services in the us-west-2 (Oregon, United States) region. A second, U.S.-based front door (strategyhub.io) is available for customers who require their application tier to be served from U.S. infrastructure.
Describing Lovable platform capabilities here is factual; it is not a Lovable-issued certification of StrategyHub™.
Subprocessors & integrations
StrategyHub™ uses third-party services to deliver the product, including the Lovable Cloud platform (database, auth, storage, functions) and transactional email delivery for invites, reminders, and unsubscribe links.
Workspaces can optionally connect external data sources (e.g. Google Sheets, BigQuery, Snowflake) to refresh KPI values. Those connections are scoped to the workspace that configured them.
For the current subprocessor list or a DPA, contact privacy@strategyhub.io.
Customer data, export & retention
StrategyHub™ stores the strategy data customers enter (goals, KPIs, initiatives, plans, comments, attachments) plus the account information needed to operate the product. Customers retain ownership of the data they enter.
Workspace admins can download a complete machine-readable export of everything their workspace owns at any time from Settings → Data portability. Individual records can be deleted in the product; full workspace and account deletion is performed by StrategyHub™ on written request. Operational logs may be retained for a limited period for security and debugging.
AI features & customer data
AI-assisted features (executive summaries, imports, meeting copilot, drafting) send only the strategy text needed for the request to the Lovable AI Gateway, which routes to Google Gemini models. Requests are made server-side with a StrategyHub™ API credential; customer data is not published to public models or used by StrategyHub™ to train any model.
Model-provider retention and training terms are governed by the AI Gateway provider's commercial API terms. Zero-retention guarantees are not asserted here. AI features are per-request only — customers who prefer no AI processing can leave those features unused.
Privacy requests
To exercise a data access, correction, deletion, or portability request, or to ask a privacy question, email privacy@strategyhub.io. We respond within a reasonable timeframe consistent with applicable law.
Security contact & vulnerability reporting
Report suspected vulnerabilities or security incidents to security@strategyhub.io. Please include reproduction steps and avoid testing against other customers' data.
Shared responsibility
StrategyHub™ is responsible for keeping the application secure, applying platform updates, enforcing tenant isolation, and exposing the access controls described above.
Customers are responsible for managing their users and roles, enabling MFA and IP allowlists where appropriate, choosing what data to enter, and complying with the regulations that apply to their business.
The underlying Lovable Cloud platform is responsible for the managed infrastructure (Postgres, auth, storage, serverless functions).
Compliance, certification, and regulatory claims (e.g. SOC 2, ISO 27001, GDPR, HIPAA) are not asserted on this page. If you need contractual commitments or audit evidence, contact sales@strategyhub.io.
