/ legal / security

Security

Last updated: September 8, 2026

About this page

This security page is maintained by SplitProof Inc. to answer common security and privacy questions about SplitProof Agree ("the app"). It describes the controls and practices that are visible in the app today. For platform infrastructure details, we rely on the capabilities provided by Lovable Cloud. This page is app-owned content and is not an independent certification, audit statement, or guarantee.

Shared responsibility

Security is a shared responsibility. Lovable Cloud provides and secures the underlying infrastructure, including the database, authentication services, and email delivery primitives. SplitProof Inc. configures the application-level access controls, data handling practices, and user-facing security features described below.

Access and authentication

  • You can draft a production agreement without creating an account or logging in.
  • Sending an agreement for electronic signature and accessing admin features require authentication and appropriate authorization.
  • Admin access is role-based. The first user who signs up is assigned the admin role; subsequent users are not granted admin privileges automatically.
  • Session tokens are handled by the authentication provider and are not stored or logged by the app.

Platform and hosting context

The app runs on Lovable Cloud infrastructure. Data is stored in the project database and served through the project's configured domains. The underlying platform manages infrastructure patching, network isolation, and availability.

Data collection and use

The app only asks for information that is missing from an imported SplitProof file or PDF export. Data you provide is used solely to generate, review, and deliver the production agreement. We do not sell personal information, use it for advertising profiling, or train generative models on your contract content.

Subprocessors and integrations

The app currently relies on Lovable Cloud for hosting, database, authentication, and email delivery. A current list of subprocessors is available on request by contacting the address below.

Cookies and analytics

The app does not use marketing cookies. We may use essential session and error-reporting cookies to keep the service stable. Analytics, if enabled, are limited to product improvement and do not track individuals across sites.

Retention and deletion

Draft agreements and signer records are retained for as long as needed to provide the signing and audit functionality. You can request deletion of a project or signer record by contacting us; we will process verifiable requests in accordance with applicable law.

Encryption

Data is encrypted in transit using TLS. Data at rest is protected by the encryption mechanisms provided by the hosting platform. The app footer displays AES-256 as the configured encryption label for the service.

Vulnerability reporting

If you discover a security issue or suspect unauthorized access to agreement data, please report it to info@splitproof.co. Include enough detail to help us understand and reproduce the issue. We do not currently operate a public bug bounty program.

Incident and security contact

For security incidents, privacy requests, or data-deletion requests, contact SplitProof Inc. at info@splitproof.co.

Compliance and certifications

SplitProof Agree does not currently hold any third-party security certifications, attestations, or compliance audits such as SOC 2 or ISO 27001. We will update this page if that changes.

Changes to this page

We may update this security page as the app evolves. The "Last updated" date at the top of the page reflects the most recent revision. Continued use of the app after changes means you accept the revised page.