Security & reliability

How your documentation is protected

This page is maintained by CableVault to answer the security, privacy and reliability questions contractors and their customers ask before trusting us with project records. It describes the controls currently in place — it is not a certification or an independent audit.

Workspace isolation

Every record is scoped to your company and enforced by row-level security in the database, not just in the interface. Customer portal users can only reach projects belonging to their own company.

Authentication

Email and password or Google sign-in, with email verification on new accounts and self-service password reset. Company administrators control who has employee access and can revoke it immediately.

Role-based access

Roles are stored separately from user profiles and cannot be changed by the account holder. Administrators manage the team; employees get working access; customers get read-only portal access.

Hosting and encryption

The application and database run on Lovable Cloud's managed infrastructure. Traffic is served over HTTPS, and uploaded documents are held in a private storage bucket that is never publicly listable — files are served through short-lived signed links.

Backups and durability

The database and document storage are operated by our managed hosting provider with automated backups. Archived projects remain available to you and your customers rather than being purged when a job closes.

Retention and deletion

Your documents stay for as long as your workspace is active. You can export a full JSON copy of your workspace data at any time from Settings, and request account deletion from the same page — deletion removes workspace data as described in the Privacy Policy.

Availability

We aim to keep CableVault continuously available and perform maintenance with as little disruption as practical, but we do not currently publish a contractual uptime guarantee. If you need a written service level commitment for a contract, contact support@cable-vault.com and we will discuss it directly.

Subprocessors and payments

Application hosting, database, file storage and transactional email are provided through Lovable Cloud. Payments and subscription billing are processed by Stripe — card details are entered on Stripe-hosted checkout and are never stored by CableVault. Search and analytics tooling is described in the Cookie Notice.

Shared responsibility

  • CableVault is responsible for the platform: tenant isolation, access controls, secure hosting, and the integrity of stored documents.
  • You are responsible for who you invite, the accuracy and legality of what you upload, and removing access when a team member leaves.
  • Your customers are responsible for the confidentiality of their portal sign-in credentials.

Reporting a security concern

Report a suspected vulnerability or unauthorized access to support@cable-vault.com. Privacy requests — access, correction, export or deletion — go to privacy@cable-vault.com and are handled as described in the Privacy Policy and Data Processing Addendum.