Security
Security is not a feature. It is a foundation.
Lovey is designed for organisations that cannot afford to compromise on data sovereignty, access control, or auditability.
Our security posture
Architecture
- Zero-trust request authentication on every endpoint
- Tenant data isolation β cross-tenant access is architecturally impossible
- Server-side authorisation β client-supplied roles and org IDs are always rejected
- Role-based access control with four membership levels
- Immutable audit trail for every platform action
Authentication
- Clerk-powered authentication with industry-standard JWTs
- Support for SSO / SAML on Team and Enterprise plans
- Multi-factor authentication available on all accounts
- Session token rotation on every request
- Automated suspicious login detection
Data residency
- All customer data stored exclusively within the European Union
- Lovey AB is registered and incorporated in Sweden
- No data transfer to third-country jurisdictions without explicit consent
- Standard Contractual Clauses (SCCs) available for enterprise agreements
- Data Processing Agreement (DPA) provided on request
Network & transport
- TLS 1.3 enforced on all connections
- HSTS with 12-month max-age and subdomain inclusion in production
- Content Security Policy (CSP) with strict source allowlists
- Clickjacking protection via X-Frame-Options: DENY
- Rate limiting on all authentication and API endpoints
Compliance
- GDPR-compliant data handling across all tiers
- Right to erasure honoured within 30 days of request
- Data minimisation β we collect only what is strictly necessary
- Lawful basis documented for all personal data processing
- Regular internal security reviews and external assessment planned
Incident response
- 72-hour GDPR breach notification to supervisory authority
- Affected users notified without undue delay
- Documented incident response runbook
- Post-incident review and public disclosure for significant events
- security@lovey.se monitored by the engineering team
Responsible disclosure
If you discover a security vulnerability in Lovey, please report it to us privately. We commit to acknowledging your report within 48 hours, providing a timeline for resolution, and crediting you in our disclosure if you wish.
Report a vulnerabilitysecurity@lovey.se β PGP key available on request
Security questions?
We are happy to discuss our security architecture, compliance posture, or Data Processing Agreement with your team.
Contact our security team β