Company · Security

Security

Practical safeguards without unsupported guarantees.

Last updated · 9 September 2026 · Version 3.0

Security is a continuing risk-management process. This page describes controls visible in the current service and avoids promising certifications, locations, backup schedules or response times that Cevor cannot independently guarantee.

1. Managed infrastructure

Cevor uses Lovable Cloud infrastructure for application backend, authentication, database and storage, hosting and delivery infrastructure for the public service, and Resend for transactional email. Infrastructure components and processing locations can vary by provider and service.

2. Transport and credentials

  • Public traffic uses HTTPS/TLS where supported by the service.
  • Authentication is handled through managed identity infrastructure; passwords, where used, are not stored by Cevor in readable form.
  • Secrets are kept in managed configuration rather than intentionally embedded in public client code.

3. Access control

Database access policies and server-side role checks restrict protected records. Administrative access is intended to be limited to authorized roles. No control eliminates all risk, and Cevor reviews issues when identified.

4. Logging and dependencies

Operational, authentication, form and email-event logs may support security, troubleshooting and abuse prevention. Dependencies and alerts are reviewed proportionately; this page does not claim continuous human monitoring.

5. Backups and deletion

Managed providers may maintain resilience copies or backups. Cevor does not promise a fixed encryption configuration or exact 30-day deletion from every backup here. Valid deletion requests are applied to active data and restricted residual copies expire through applicable provider backup cycles, subject to law.

6. Vulnerability reports

Report the affected page or function, steps to reproduce and likely impact without accessing other people’s data. Cevor acknowledges and investigates within a reasonable period; no fixed three-day response or remediation deadline is guaranteed.

7. Incidents

Cevor investigates and contains suspected incidents. Where a personal-data breach must be notified, Cevor follows GDPR duties, including notification to the competent authority within 72 hours where Article 33 applies, and notification to affected people where legally required.

8. Certifications

Cevor does not currently claim SOC 2, ISO 27001, HIPAA or another formal security certification. This Trust Center is not an independent security audit.

Contact

For questions, write to hello@cevor.app

See also