On Your Terms
Home / Legal

Security

Last updated June 30, 2026

This page summarizes the controls On Your Terms has enabled today. It is maintained by On Your Terms to answer common security and privacy questions. It is not an independent certification.

Authentication & access

  • Email/password sign-in with leaked-password (HIBP) check.
  • Google sign-in via the managed Lovable Cloud OAuth broker.
  • Server-side validation of every authenticated API request via signed tokens.

Data protection

  • TLS in transit for all traffic.
  • Encrypted at rest by our managed infrastructure provider.
  • Row-Level Security (RLS) on every customer-data table; access scoped to the authenticated user.
  • Role-based access for admin features; "master admin" is restricted to the founder account.

Sub-processors

See Trust Center for the current sub-processor list.

Vulnerability reporting

Email security@onyourterms.app. We acknowledge within 2 business days and aim to resolve critical issues within 14 days.

Compliance roadmap

  • SOC 2 Type I — planned 2026.
  • GDPR/CCPA — operational from launch via our Privacy Policy and DPA.

Disclaimer

This page describes controls we have enabled — it is not a substitute for an independent audit or certification.