Trust & Security

How we protect your operational data

This page is maintained by the OPSFlow360 team to answer common security and privacy questions about the platform. It describes controls currently in place and is editable project content — it is not an independent certification or third-party audit attestation.

Authentication & access

Access to OPSFlow360 requires an authenticated account. Sign-in supports email/password and Google. Sessions are issued and validated by our managed identity provider.

Role-based permissions (super admin, admin, auditor, user) gate sensitive actions such as user management, role assignment, and tenant settings.

Tenant isolation

Every record is scoped to a tenant. Database row-level security policies require an authenticated user with explicit membership in the tenant before any row is returned or written, including indirect access through related tables.

Privileged operations (role permission changes, secret management) require a verified super-admin role in addition to tenant membership.

Platform & hosting

OPSFlow360 runs on Lovable Cloud. Application traffic is served over TLS, and database, auth, storage, and serverless functions are operated by the underlying managed platform.

Server-side secrets (API keys, service credentials) are kept out of the client bundle and only accessed from server functions.

Data we collect

We process operational data you enter or upload: organization and project records, employees, suppliers, vehicles, trips, expenses, invoices, receipts, documents, and audit logs.

We also process account metadata (email, name, avatar) needed to sign you in and attribute activity inside your tenant.

Subprocessors & integrations

Third-party integrations are opt-in per tenant (for example, mapping or telemetry providers). When a tenant administrator enables an integration, the relevant data needed for that feature is shared with the configured provider.

For the current list of subprocessors or a Data Processing Addendum, contact the OPSFlow360 team.

Reporting a security issue

If you believe you have found a security vulnerability, please email the OPSFlow360 team. Include steps to reproduce and any relevant logs or screenshots. Please do not publicly disclose the issue before we have had a chance to investigate.

Shared responsibility. Lovable provides the underlying cloud, identity, database, and storage primitives. The OPSFlow360 team configures application-level access rules and features. Customer administrators are responsible for managing their users, role assignments, and the data they choose to upload.

This page describes current controls and is updated as the product evolves. Statements here are not a certification, audit report, or contractual commitment.