Welcome

Trust & Security

Last updated: 26 July 2026

This page is maintained by EGNITE to answer common security and privacy questions about the EGNITE platform. It describes the controls that are currently enabled and how we handle your data.

Where your data is stored

  • Your database — accounts, brands, prompts, scan history, reports — is hosted in the European Union (Ireland, AWS eu-west-1) by the Lovable Cloud backend.
  • Authentication records and uploaded files live in the same EU region. We do not replicate the customer database outside the EEA.
  • The website itself is delivered from a global edge network for speed; only request metadata (IP, headers) is handled there, never your workspace data.
  • Backups are managed by the hosting provider and stay within the same region.

International transfers

A small number of service providers operate outside the EEA — email delivery, edge protection, and the AI engines. Those transfers rely on the European Commission's Standard Contractual Clauses (and, where applicable, the EU-US Data Privacy Framework), with one important supplementary measure: the AI providers receive only prompt text and public brand context, never an email address, account ID, or any other personal data. The full list, with each provider's region and transfer basis, is on the Subprocessors page.

Platform & hosting

  • The application is built on Lovable Cloud and runs on a managed backend infrastructure.
  • Database, authentication, and storage are provided by the Lovable Cloud backend service.
  • All public traffic is served over HTTPS with TLS encryption.
  • The platform receives regular automated security scans; findings are reviewed and remediated.

Access & authentication

  • Accounts are protected by email/password or social sign-in via the Lovable Auth broker.
  • Passwords are never stored in plain text; the backend handles hashing and secure credential storage.
  • Sessions are short-lived and refreshed automatically.
  • Admin roles are stored in a separate table and checked server-side; regular users cannot escalate privileges.

What we collect & store

  • Account data: email, name, company, and optional profile fields you provide.
  • Workspace data: brands, products, competitors, prompts, and scan results you create.
  • Usage data: scan timestamps, model selections, and recommendation history.
  • Billing metadata: plan, subscription status, and Paddle customer ID. We do not store card numbers.

AI provider data handling

This is the part most clients ask about. Here is exactly what happens when you run a scan:

  • We send only the prompt text, the brand name, and any public context you entered (products, competitors, market, region).
  • We do not send your email, company name, account ID, or any other personal information to the AI providers.
  • We route calls through the Lovable AI Gateway or direct enterprise API endpoints that do not use your data to train foundation models.
  • Each user's prompts, scan results, and brand data are stored in rows that only that user (or an admin) can read. Your competitors cannot see your data, and neither can other users on the platform.

Supported engines: ChatGPT (OpenAI), Claude (Anthropic), Perplexity, Gemini (Google), Copilot (OpenAI), Grok (xAI), and DeepSeek.

Encryption & isolation

  • All data is encrypted in transit using TLS.
  • Data is encrypted at rest by the backend provider.
  • Every user-facing table has Row-Level Security (RLS) enabled: queries are filtered by the authenticated user ID, so one user cannot read another user's rows.
  • Privileged operations (admin actions, webhooks) run under service-role credentials and are never exposed to the browser.
  • Passwords are checked against the Have I Been Pwned breach corpus at sign-up and password change, so known-compromised passwords are rejected.
  • Tenant isolation is verified by an automated two-account test across every customer table: a signed-in account cannot read or modify another account's rows, and cannot change its own plan or role.

Retention & deletion

  • Account, workspace, and scan data are retained for as long as your account exists — nothing is auto-deleted, so your AI visibility history stays comparable over time.
  • Deleting your account erases your profile, brands, prompts, scan and crawl history, competitor data, expert verifications, support threads, and subscription record immediately and irreversibly.
  • Records submitted with your email through public forms (newsletter, contact, expert requests) are deleted in the same operation, and your address is added to a do-not-contact list.
  • Only anonymous page-view counters remain, with the account reference stripped.
  • Billing records are kept for the period required by tax law.

Your privacy controls

You can export a full copy of your data or delete your account at any time from Settings → Privacy. You can also email us at privacy@egnitegroup.com.

Response commitments

  • Data-subject requests (access, rectification, export, erasure, objection) are answered within 30 days of receipt, as required by GDPR Article 12. Export and deletion are also available instantly in-app.
  • Personal data breaches affecting customer data are notified to affected controllers without undue delay and within 72 hours of us becoming aware, with the facts known at that time.
  • Security reports are acknowledged within 3 business days — see /.well-known/security.txt or email security@egnitegroup.com.
  • Security questionnaires and countersigned DPAs are returned within 5 business days.

Subprocessors & integrations

Every third party we use, with its purpose, the data it receives, its processing region and transfer basis, is listed on the Subprocessors page. We notify customers before adding a new subprocessor that handles personal data, and you may object.

  • Lovable Cloud / backend — hosting, database, authentication, server functions (EU, Ireland).
  • Paddle — subscription billing and tax handling.
  • Resend / Lovable Email — transactional and newsletter emails.
  • AI providers — OpenAI, Anthropic, Google, Perplexity, xAI, DeepSeek — receive only prompt/brand context as described above.

Shared responsibility

Platform security (infrastructure, database hardening, auth, TLS) is managed by Lovable Cloud and the backend provider. EGNITE configures access controls, RLS policies, and secure coding practices on top of that platform. You remain responsible for keeping your password safe and for the content of the prompts and brand data you submit.

Security contact

Report a vulnerability to security@egnitegroup.com (see /.well-known/security.txt). For privacy questions email privacy@egnitegroup.com or contact us.

This page is provided for transparency and is not an independent security certification, audit report, or legal contract. See also: Privacy Policy, Data Processing Agreement, Subprocessors, Cookie Policy, and Terms of Service.