Skip to main content
Trust

Security & Trust

This page is maintained by CheckSmith.ai to answer common security and privacy questions about the product. It describes the controls we have in place today — not certifications we have not earned.

Overview PDF version 1.0 · Updated July 22, 2026

Shared Responsibility Model

Security is a shared responsibility. Lovable Cloud manages the platform infrastructure that runs CheckSmith.ai. CheckSmith.ai manages the application layer — the code, database access rules, audit logging, and AI features. Each workspace owner manages their own account security, team memberships, and the data they choose to share.

Platform

Infrastructure, network security, database encryption at rest, and the identity broker.

Application

Application code, row-level security policies, audit logs, and AI-gateway routing.

Customer

Strong credentials, two-factor auth, team access reviews, and careful link sharing.

Access & Authentication

Every request to CheckSmith.ai is tied to an authenticated user. Sessions are signed, short-lived, and revocable.

  • Email + password and Google sign-in, brokered through our identity provider.
  • Sessions are short-lived JSON Web Tokens; signing out clears cached data.
  • Role-based access: owner, admin, accountant, and member — enforced per workspace.
  • Admin actions are recorded in an audit log retained for at least one year.

Multi-Tenant Data Isolation

Every customer-owned table is scoped to a workspace. The database rejects cross-workspace reads and writes, so one company can never see another company's data.

  • Row-level security policies enforced at the database, not just the app.
  • Membership checked on every query through a security-definer helper.
  • Shareable links (proposals, IRA snapshots) use unguessable tokens with narrow, read-only access.

Encryption

Data is encrypted in transit and at rest using standard algorithms provided by our managed cloud platform.

  • TLS 1.2+ for every browser and API request.
  • Database and file storage encryption at rest using the platform's default algorithms.
  • Secrets are stored in an encrypted secret manager and are only read by the application at runtime.

Data We Store

We store the data you enter into CheckSmith.ai and the minimum operational data needed to run the service.

  • Business records you create: invoices, clients, ledger entries, bank reconciliation data, payroll runs and paycheck records, checks, IRA holdings, and uploaded documents.
  • Account data: email, name, workspace membership, and role.
  • Operational data: sign-in timestamps, admin audit events, and error diagnostics.
  • We do not sell customer data and do not use it to train third-party AI models.

Hosting & Subprocessors

CheckSmith.ai runs on Lovable Cloud managed infrastructure. We disclose the subprocessors that store or process customer data so you can review them.

  • Application and database hosted on Lovable Cloud.
  • Optional bank data via Plaid — only for workspaces that link an account.
  • Transactional email delivered through Lovable's managed email infrastructure.
  • AI features via Lovable AI Gateway; prompt content is not used to train the underlying models.
  • Payment processing through a third-party payment processor when online payments are enabled.

Cookies & Analytics

We use a small number of cookies and analytics tools to keep sessions secure and understand how the product is used.

  • Session cookies are required for authentication and security.
  • First-party analytics beacon records pageviews and feature usage to improve the service.
  • Third-party analytics (Google Analytics 4, Plausible) are loaded only when configured for the workspace.
  • You can disable third-party analytics in your browser or through your workspace settings where available.

Retention & Deletion

You control your data. Deleted records leave the live database immediately; backups age out on a fixed schedule.

  • Workspace deletion removes your data from the live database right away.
  • Encrypted backups roll off within 35 days of deletion.
  • Admin audit log entries are retained for one year and then archived or purged.
  • Export your data at any time from Settings → Export.

Payments

We do not store card numbers. When online payments are enabled, card data is handled by the payment processor's hosted fields.

  • Card data is entered directly into the payment processor's secure iframe or hosted page.
  • CheckSmith.ai only receives a tokenized customer and subscription reference.

Compliance Status — What We Claim Today

We describe the controls we have in place. We do not claim certifications we have not earned.

  • CheckSmith.ai is not yet SOC 2, ISO 27001, HIPAA, or PCI-DSS certified.
  • We are not a HIPAA business associate and do not sign business-associate agreements today.
  • For enterprise procurement questions, contact us and we will share what we can document.

Incident Response

If we confirm a security incident that affects customer data, we notify affected workspace owners without undue delay.

  • Owners are notified by email at the address on file.
  • Notice includes what we know, what we're doing, and what you should do.

Security & Trust FAQ

Practical answers for small and medium-sized businesses evaluating CheckSmith.ai.

Contact Our Security & Trust Team

Every submission is routed to the right team based on the topic you pick. Acknowledged within two business days.

Routed to our Trust team

We can return a completed SIG-Lite, CAIQ, or your own vendor questionnaire, along with our latest Trust overview.

By submitting, you agree we may store your message to reply. See our privacy notice.

Prefer email? Vulnerability reports can also go to security@checksmith.com. We will not pursue action against good-faith researchers who follow responsible-disclosure norms.

Subprocessors & Hosting Locations

Third parties that store or process customer data on behalf of CheckSmith.ai, and the regions where that processing happens.

List last reviewed: July 22, 2026. The downloaded CSV is stamped with the exact date and time you export it.

NamePurposeData ProcessedHosting RegionEngagement
Lovable CloudApplication hosting, database, file storage, and authentication broker.All workspace data (invoices, clients, ledger entries, uploaded files, audit log, account credentials).United States (multi-region, primary us-east)Core
Lovable AI GatewayRoutes AI features (invoice extraction, categorization, drafting). Prompts are not used to train underlying models.Prompt content sent to AI features and the model's response. No long-term retention for training.United StatesCore
Lovable Email InfrastructureTransactional email delivery (invitations, notifications, receipts).Recipient email address, subject, and message body.United States / European UnionCore
Plaid, Inc.Bank account linking, balance and transaction retrieval.Financial institution credentials handled by Plaid, account and transaction metadata surfaced back to CheckSmith.ai.United StatesOptional
Stripe, Inc.Online payment processing when workspaces enable card payments.Card data entered directly into Stripe's hosted fields; CheckSmith.ai receives tokenized customer and payment references only.United StatesOptional
Google Analytics 4 (Google LLC)Aggregated product usage analytics when enabled by the workspace.Pageview and event metadata, IP-derived approximate location, browser and device attributes.United States (with regional edge collection)Optional
Plausible AnalyticsPrivacy-friendly aggregated pageview analytics when enabled by the workspace.Anonymous pageview counts, referrer, and coarse device/browser info. No cookies or personal identifiers.European Union (Germany)Optional

"Core" subprocessors run for every workspace. "Optional" subprocessors are only engaged when a workspace turns on the related feature (bank linking, online payments, or third-party analytics).

Overview PDF Version History

Every revision of the Security & Trust Overview PDF, with a summary of what changed. Older versions remain downloadable for your records.

  1. v1.0July 22, 2026CurrentDownload v1.0

    Initial public release of the Security & Trust overview covering access, isolation, encryption, retention, and incident response.

    • Documented shared-responsibility model across platform, application, and customer.
    • Listed current subprocessors and hosting posture.
    • Described retention, deletion, and audit-log practices.
    • Added incident-response and vulnerability-reporting contacts.

The unversioned link /downloads/checksmith-security-trust-overview.pdf always points at the current release.

Questions about this page or enterprise procurement? Contact us.