Security & Trust
This page is maintained by CheckSmith.ai to answer common security and privacy questions about the product. It describes the controls we have in place today — not certifications we have not earned.
Overview PDF version 1.0 · Updated July 22, 2026
Shared Responsibility Model
Security is a shared responsibility. Lovable Cloud manages the platform infrastructure that runs CheckSmith.ai. CheckSmith.ai manages the application layer — the code, database access rules, audit logging, and AI features. Each workspace owner manages their own account security, team memberships, and the data they choose to share.
Platform
Infrastructure, network security, database encryption at rest, and the identity broker.
Application
Application code, row-level security policies, audit logs, and AI-gateway routing.
Customer
Strong credentials, two-factor auth, team access reviews, and careful link sharing.
Access & Authentication
Every request to CheckSmith.ai is tied to an authenticated user. Sessions are signed, short-lived, and revocable.
- Email + password and Google sign-in, brokered through our identity provider.
- Sessions are short-lived JSON Web Tokens; signing out clears cached data.
- Role-based access: owner, admin, accountant, and member — enforced per workspace.
- Admin actions are recorded in an audit log retained for at least one year.
Multi-Tenant Data Isolation
Every customer-owned table is scoped to a workspace. The database rejects cross-workspace reads and writes, so one company can never see another company's data.
- Row-level security policies enforced at the database, not just the app.
- Membership checked on every query through a security-definer helper.
- Shareable links (proposals, IRA snapshots) use unguessable tokens with narrow, read-only access.
Encryption
Data is encrypted in transit and at rest using standard algorithms provided by our managed cloud platform.
- TLS 1.2+ for every browser and API request.
- Database and file storage encryption at rest using the platform's default algorithms.
- Secrets are stored in an encrypted secret manager and are only read by the application at runtime.
Data We Store
We store the data you enter into CheckSmith.ai and the minimum operational data needed to run the service.
- Business records you create: invoices, clients, ledger entries, bank reconciliation data, payroll runs and paycheck records, checks, IRA holdings, and uploaded documents.
- Account data: email, name, workspace membership, and role.
- Operational data: sign-in timestamps, admin audit events, and error diagnostics.
- We do not sell customer data and do not use it to train third-party AI models.
Hosting & Subprocessors
CheckSmith.ai runs on Lovable Cloud managed infrastructure. We disclose the subprocessors that store or process customer data so you can review them.
- Application and database hosted on Lovable Cloud.
- Optional bank data via Plaid — only for workspaces that link an account.
- Transactional email delivered through Lovable's managed email infrastructure.
- AI features via Lovable AI Gateway; prompt content is not used to train the underlying models.
- Payment processing through a third-party payment processor when online payments are enabled.
Cookies & Analytics
We use a small number of cookies and analytics tools to keep sessions secure and understand how the product is used.
- Session cookies are required for authentication and security.
- First-party analytics beacon records pageviews and feature usage to improve the service.
- Third-party analytics (Google Analytics 4, Plausible) are loaded only when configured for the workspace.
- You can disable third-party analytics in your browser or through your workspace settings where available.
Retention & Deletion
You control your data. Deleted records leave the live database immediately; backups age out on a fixed schedule.
- Workspace deletion removes your data from the live database right away.
- Encrypted backups roll off within 35 days of deletion.
- Admin audit log entries are retained for one year and then archived or purged.
- Export your data at any time from Settings → Export.
Payments
We do not store card numbers. When online payments are enabled, card data is handled by the payment processor's hosted fields.
- Card data is entered directly into the payment processor's secure iframe or hosted page.
- CheckSmith.ai only receives a tokenized customer and subscription reference.
Compliance Status — What We Claim Today
We describe the controls we have in place. We do not claim certifications we have not earned.
- CheckSmith.ai is not yet SOC 2, ISO 27001, HIPAA, or PCI-DSS certified.
- We are not a HIPAA business associate and do not sign business-associate agreements today.
- For enterprise procurement questions, contact us and we will share what we can document.
Incident Response
If we confirm a security incident that affects customer data, we notify affected workspace owners without undue delay.
- Owners are notified by email at the address on file.
- Notice includes what we know, what we're doing, and what you should do.
Security & Trust FAQ
Practical answers for small and medium-sized businesses evaluating CheckSmith.ai.
Prefer email? Vulnerability reports can also go to security@checksmith.com. We will not pursue action against good-faith researchers who follow responsible-disclosure norms.
Subprocessors & Hosting Locations
Third parties that store or process customer data on behalf of CheckSmith.ai, and the regions where that processing happens.
List last reviewed: July 22, 2026. The downloaded CSV is stamped with the exact date and time you export it.
| Name | Purpose | Data Processed | Hosting Region | Engagement |
|---|---|---|---|---|
| Lovable Cloud | Application hosting, database, file storage, and authentication broker. | All workspace data (invoices, clients, ledger entries, uploaded files, audit log, account credentials). | United States (multi-region, primary us-east) | Core |
| Lovable AI Gateway | Routes AI features (invoice extraction, categorization, drafting). Prompts are not used to train underlying models. | Prompt content sent to AI features and the model's response. No long-term retention for training. | United States | Core |
| Lovable Email Infrastructure | Transactional email delivery (invitations, notifications, receipts). | Recipient email address, subject, and message body. | United States / European Union | Core |
| Plaid, Inc. | Bank account linking, balance and transaction retrieval. | Financial institution credentials handled by Plaid, account and transaction metadata surfaced back to CheckSmith.ai. | United States | Optional |
| Stripe, Inc. | Online payment processing when workspaces enable card payments. | Card data entered directly into Stripe's hosted fields; CheckSmith.ai receives tokenized customer and payment references only. | United States | Optional |
| Google Analytics 4 (Google LLC) | Aggregated product usage analytics when enabled by the workspace. | Pageview and event metadata, IP-derived approximate location, browser and device attributes. | United States (with regional edge collection) | Optional |
| Plausible Analytics | Privacy-friendly aggregated pageview analytics when enabled by the workspace. | Anonymous pageview counts, referrer, and coarse device/browser info. No cookies or personal identifiers. | European Union (Germany) | Optional |
"Core" subprocessors run for every workspace. "Optional" subprocessors are only engaged when a workspace turns on the related feature (bank linking, online payments, or third-party analytics).
Overview PDF Version History
Every revision of the Security & Trust Overview PDF, with a summary of what changed. Older versions remain downloadable for your records.
Initial public release of the Security & Trust overview covering access, isolation, encryption, retention, and incident response.
- Documented shared-responsibility model across platform, application, and customer.
- Listed current subprocessors and hosting posture.
- Described retention, deletion, and audit-log practices.
- Added incident-response and vulnerability-reporting contacts.
The unversioned link /downloads/checksmith-security-trust-overview.pdf always points at the current release.
Questions about this page or enterprise procurement? Contact us.