Security
Last updated: September 8, 2026
About this page
This security page is maintained by SplitProof Inc. to answer common security and privacy questions about SplitProof Agree ("the app"). It describes the controls and practices that are visible in the app today. For platform infrastructure details, we rely on the capabilities provided by Lovable Cloud. This page is app-owned content and is not an independent certification, audit statement, or guarantee.
Shared responsibility
Security is a shared responsibility. Lovable Cloud provides and secures the underlying infrastructure, including the database, authentication services, and email delivery primitives. SplitProof Inc. configures the application-level access controls, data handling practices, and user-facing security features described below.
Access and authentication
- You can draft a production agreement without creating an account or logging in.
- Sending an agreement for electronic signature and accessing admin features require authentication and appropriate authorization.
- Admin access is role-based. The first user who signs up is assigned the admin role; subsequent users are not granted admin privileges automatically.
- Session tokens are handled by the authentication provider and are not stored or logged by the app.
Platform and hosting context
The app runs on Lovable Cloud infrastructure. Data is stored in the project database and served through the project's configured domains. The underlying platform manages infrastructure patching, network isolation, and availability.
Data collection and use
The app only asks for information that is missing from an imported SplitProof file or PDF export. Data you provide is used solely to generate, review, and deliver the production agreement. We do not sell personal information, use it for advertising profiling, or train generative models on your contract content.
Subprocessors and integrations
The app currently relies on Lovable Cloud for hosting, database, authentication, and email delivery. A current list of subprocessors is available on request by contacting the address below.
Cookies and analytics
The app does not use marketing cookies. We may use essential session and error-reporting cookies to keep the service stable. Analytics, if enabled, are limited to product improvement and do not track individuals across sites.
Retention and deletion
Draft agreements and signer records are retained for as long as needed to provide the signing and audit functionality. You can request deletion of a project or signer record by contacting us; we will process verifiable requests in accordance with applicable law.
Encryption
Data is encrypted in transit using TLS. Data at rest is protected by the encryption mechanisms provided by the hosting platform. The app footer displays AES-256 as the configured encryption label for the service.
Vulnerability reporting
If you discover a security issue or suspect unauthorized access to agreement data, please report it to info@splitproof.co. Include enough detail to help us understand and reproduce the issue. We do not currently operate a public bug bounty program.
Incident and security contact
For security incidents, privacy requests, or data-deletion requests, contact SplitProof Inc. at info@splitproof.co.
Compliance and certifications
SplitProof Agree does not currently hold any third-party security certifications, attestations, or compliance audits such as SOC 2 or ISO 27001. We will update this page if that changes.
Changes to this page
We may update this security page as the app evolves. The "Last updated" date at the top of the page reflects the most recent revision. Continued use of the app after changes means you accept the revised page.