This page is maintained by doimpact.llc to answer common security and privacy questions about the platform.

Security

Security is a shared responsibility. doimpact.llc secures the platform infrastructure and application, while customers are responsible for their own account credentials, user access management, and the lawfulness of data they upload.

Access and authentication

DO.Impact uses email/password authentication and Google sign-in through Lovable Cloud. Passwords are hashed and stored by the identity provider. Each user can only access workspaces they have been invited to or created, and access levels are enforced by row-level security policies in the database. Workspace admins can grant or revoke access and control which modules each user sees.

Platform and hosting context

The application is built on TanStack Start and runs on Lovable Cloud infrastructure. Data is stored in a managed database with encryption at rest and in transit. Backups are managed by the platform provider. doimpact.llc does not run its own physical infrastructure.

Data isolation

DO.Impact is a multi-tenant application. Each customer workspace is isolated by a company identifier. Database queries are scoped to the active company through row-level security policies and application checks. Admins cannot see another workspace’s data unless explicitly invited.

Audit logging

Sensitive events such as logins, company switches, access changes, data exports, and entitlement edits are written to an audit log. Workspace admins can review these logs from the administration area. Logs are scoped to the workspace and retained according to the workspace retention policy.

Data collection and use

The platform collects account data, workspace data, and any content the customer uploads. We process this data only to provide and improve the service. See the Privacy Policy for more details.

Subprocessors and integrations

The platform uses Lovable Cloud for hosting, authentication, and storage. The optional Exec Team Room AI add-on uses AI model providers. Billing is processed by Stripe. A current list is available in the Data Processing Agreement.

Retention and deletion

Workspace data is retained while the account is active. Account owners can delete their workspace or request personal data deletion through the settings or security contact page. Anonymized, aggregated statistics may be retained for operational purposes. Sandbox data is session-only and not saved.

Privacy requests

Users can request access, correction, deletion, or export of their personal data by contacting their workspace admin or through /security-contact.

Incident and security contact

Suspected security issues or breaches can be reported through /security-contact or by email to contact@doimpact.app. We aim to acknowledge reports within 24 hours and will notify affected workspace admins of confirmed breaches without undue delay.

Vulnerability reporting

We welcome responsible disclosure of security vulnerabilities. Please report issues through the security contact page rather than public channels. We will investigate and fix valid issues promptly.

Compliance and certifications

doimpact.llc does not currently hold SOC 2 Type II, ISO/IEC 27001, or any other third-party security certification. We do not claim to be certified, audited, or formally compliant with those standards. Independent certification is on our roadmap, and we will update this page if and when it is achieved.

The controls we operate today are: encryption in transit and at rest through our managed cloud provider, company-scoped row-level security for tenant isolation, role-based access control with admin-managed module permissions, audit logging of sensitive events, provider-managed backups, and recurring automated security scanning of the database and dependencies.

If you need a security questionnaire completed or documentation for a vendor review, contact us through /security-contact.

Report a security concern

If you have found a vulnerability or suspect a security issue, please let us know.