Security

Your safety data, treated like safety data

This page is maintained by Safety Insight Hub to describe the controls currently in place. It is not an independent certification.

Encryption in transit

All traffic to Safety Insight Hub is served over HTTPS with TLS provided by our hosting platform.

Authentication

Sign-in supports email and password, optional Google sign-in, and multi-factor authentication for any account. Password sign-in has leaked-password protection and a short-window lockout after repeated failed attempts. Users can review recent sign-in activity from Settings.

Access control

Every record is scoped to the workspace that owns it via row-level security in the database. Role-based permissions (employee, supervisor, safety manager, admin, executive, auditor) are enforced server-side, not just in the UI.

Hosting

Hosted on the Lovable Cloud platform, which runs on managed Supabase / AWS infrastructure with isolated tenants per workspace.

Backups

The underlying managed Postgres platform performs its own backups. We do not currently offer a customer-facing restore-to-point-in-time control from inside the app.

Audit trail

Changes to critical records (incidents, near misses, hazards, corrective actions, permits, and others) are logged with a timestamp, the action, and the full before/after payload. The acting user is captured where the change originated from a signed-in session; system-initiated writes are labelled "system". Admins, safety managers, and auditors can view the audit log inside the app.

Shared responsibility

Safety Insight Hub secures the application — access controls, row-level security, authentication, and the audit trail described above. The underlying encryption, hosting, and backup properties are provided by our platform (Lovable Cloud on Supabase / AWS). You're responsible for managing who in your organization has access, the strength of their credentials, and the data your team chooses to upload.

Responsible disclosure

If you believe you've found a security vulnerability, please email reviews@safetyinsightapp.com. Please give us reasonable time to investigate and remediate before public disclosure. We do not currently run a paid bug bounty, but we will credit researchers who follow this process.

Compliance

Safety Insight Hub is not currently SOC 2, ISO 27001, or HIPAA certified, and we do not claim to be. If you have specific compliance questions or a security questionnaire, contact reviews@safetyinsightapp.com.

Questions

Want to talk through a specific control? Get in touch.