Security

Security is not a feature. It is a foundation.

Lovey is designed for organisations that cannot afford to compromise on data sovereignty, access control, or auditability.

Our security posture

Architecture

  • Zero-trust request authentication on every endpoint
  • Tenant data isolation β€” cross-tenant access is architecturally impossible
  • Server-side authorisation β€” client-supplied roles and org IDs are always rejected
  • Role-based access control with four membership levels
  • Immutable audit trail for every platform action

Authentication

  • Clerk-powered authentication with industry-standard JWTs
  • Support for SSO / SAML on Team and Enterprise plans
  • Multi-factor authentication available on all accounts
  • Session token rotation on every request
  • Automated suspicious login detection

Data residency

  • All customer data stored exclusively within the European Union
  • Lovey AB is registered and incorporated in Sweden
  • No data transfer to third-country jurisdictions without explicit consent
  • Standard Contractual Clauses (SCCs) available for enterprise agreements
  • Data Processing Agreement (DPA) provided on request

Network & transport

  • TLS 1.3 enforced on all connections
  • HSTS with 12-month max-age and subdomain inclusion in production
  • Content Security Policy (CSP) with strict source allowlists
  • Clickjacking protection via X-Frame-Options: DENY
  • Rate limiting on all authentication and API endpoints

Compliance

  • GDPR-compliant data handling across all tiers
  • Right to erasure honoured within 30 days of request
  • Data minimisation β€” we collect only what is strictly necessary
  • Lawful basis documented for all personal data processing
  • Regular internal security reviews and external assessment planned

Incident response

  • 72-hour GDPR breach notification to supervisory authority
  • Affected users notified without undue delay
  • Documented incident response runbook
  • Post-incident review and public disclosure for significant events
  • security@lovey.se monitored by the engineering team

Responsible disclosure

If you discover a security vulnerability in Lovey, please report it to us privately. We commit to acknowledging your report within 48 hours, providing a timeline for resolution, and crediting you in our disclosure if you wish.

Report a vulnerability

security@lovey.se β€” PGP key available on request

Security questions?

We are happy to discuss our security architecture, compliance posture, or Data Processing Agreement with your team.

Contact our security team β†’