Your safety data, treated like safety data
This page is maintained by Safety Insight Hub to describe the controls currently in place. It is not an independent certification.
All traffic to Safety Insight Hub is served over HTTPS with TLS provided by our hosting platform.
Sign-in supports email and password, optional Google sign-in, and multi-factor authentication for any account. Password sign-in has leaked-password protection and a short-window lockout after repeated failed attempts. Users can review recent sign-in activity from Settings.
Every record is scoped to the workspace that owns it via row-level security in the database. Role-based permissions (employee, supervisor, safety manager, admin, executive, auditor) are enforced server-side, not just in the UI.
Hosted on the Lovable Cloud platform, which runs on managed Supabase / AWS infrastructure with isolated tenants per workspace.
The underlying managed Postgres platform performs its own backups. We do not currently offer a customer-facing restore-to-point-in-time control from inside the app.
Changes to critical records (incidents, near misses, hazards, corrective actions, permits, and others) are logged with a timestamp, the action, and the full before/after payload. The acting user is captured where the change originated from a signed-in session; system-initiated writes are labelled "system". Admins, safety managers, and auditors can view the audit log inside the app.
Shared responsibility
Safety Insight Hub secures the application — access controls, row-level security, authentication, and the audit trail described above. The underlying encryption, hosting, and backup properties are provided by our platform (Lovable Cloud on Supabase / AWS). You're responsible for managing who in your organization has access, the strength of their credentials, and the data your team chooses to upload.
Responsible disclosure
If you believe you've found a security vulnerability, please email reviews@safetyinsightapp.com. Please give us reasonable time to investigate and remediate before public disclosure. We do not currently run a paid bug bounty, but we will credit researchers who follow this process.
Compliance
Safety Insight Hub is not currently SOC 2, ISO 27001, or HIPAA certified, and we do not claim to be. If you have specific compliance questions or a security questionnaire, contact reviews@safetyinsightapp.com.
Questions
Want to talk through a specific control? Get in touch.