Built for businesses you can trust
This page is maintained by Kooshk Tech to answer common security, privacy, and compliance questions about our platform. It is editable content, not a third-party certification.
HTTPS everywhere, TLS 1.2+, OAuth-grade authentication, Row Level Security on every tenant table, and least-privilege service roles.
We process the minimum personal data needed to deliver the service. No selling of data, no third-party advertising trackers, EU-based processing.
We disclose AI use, keep humans in the loop for sensitive flows, and let you delete training inputs at any time.
Workspaces are isolated. Customer content is used only to power your assistants — never to train shared models.
Lawful basis, data-subject rights, EU data residency, and a public DPA template you can sign electronically.
Built on Supabase + Lovable Cloud (EU region), Stripe for billing, and Lovable AI Gateway for model access.
TLS 1.2+ in transit, AES-256 at rest, signed JWT sessions, and secrets stored in a managed vault.
Live status, scheduled maintenance, and incident history are public.
We post-mortem every customer-impacting incident on the status page.
Report a vulnerability or ask a security question. We aim to reply within 2 business days.
security@datakooshktech.tech