Security & Compliance Report
A plain-language summary of the controls SplashIQ has in place today, intended to support SOC 2, ISO 27001, and contractor due-diligence reviews. This document is maintained by SplashIQ and is not an independent audit or certification.
Scope & intent
This report describes the security, privacy, and operational controls implemented in the SplashIQ application and the managed platform it runs on. It is designed to answer the questions most commonly raised in vendor security reviews — including those that map to the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality), ISO/IEC 27001 Annex A control families, and contractor due-diligence questionnaires.
SplashIQ is not currently SOC 2 or ISO 27001 certified. Where controls align to those frameworks we say so explicitly; we do not claim audit outcomes we have not received.
Controls in place
Hosting & subprocessors
SplashIQ runs on the Lovable platform with a managed Postgres, Auth, and Storage backend. Outbound email and notifications use vetted providers under data-processing agreements. Optional integrations (QuickBooks, financing requests, marketing email) are opt-in per workspace. Credentials for connected services are stored server-side and never exposed to browsers.
Data handling & retention
Workspace owners can export or delete records from inside the app. Account deletion requests are honored within 30 days. We do not sell personal information. For privacy details, see our Privacy Policy.
Framework alignment (self-assessed)
The controls above map to the following framework areas. This mapping is self-assessed by SplashIQ and is not a substitute for an independent audit report.
- SOC 2: Security (CC6 logical access, CC7 system operations), Availability (A1), Confidentiality (C1).
- ISO/IEC 27001 Annex A: A.5 organizational controls, A.8 access control, A.10 cryptography, A.12 operations security, A.13 communications security, A.16 incident management.
- Contractor due diligence: data isolation, encryption, access management, subprocessor list, incident contact, data export/erasure.
Shared responsibility
SplashIQ provides the platform controls described above. Workspace owners are responsible for managing teammate access, using strong passwords, enabling two-factor authentication where available, and configuring integrations appropriately for their business.
Requesting more detail
Enterprise prospects and contractors performing vendor reviews can request a completed security questionnaire, subprocessor list, or DPA by emailing hello@splashiq.ai. See also our Trust & Security page.
This report reflects current practice and is updated as our controls evolve. It is provided for informational purposes and does not constitute a warranty or an independent certification.