Security Report

Security & Compliance Report

A plain-language summary of the controls SplashIQ has in place today, intended to support SOC 2, ISO 27001, and contractor due-diligence reviews. This document is maintained by SplashIQ and is not an independent audit or certification.

Report owner
SplashIQ LLC
Last updated
July 26, 2026

Scope & intent

This report describes the security, privacy, and operational controls implemented in the SplashIQ application and the managed platform it runs on. It is designed to answer the questions most commonly raised in vendor security reviews — including those that map to the SOC 2 Trust Services Criteria (Security, Availability, Confidentiality), ISO/IEC 27001 Annex A control families, and contractor due-diligence questionnaires.

SplashIQ is not currently SOC 2 or ISO 27001 certified. Where controls align to those frameworks we say so explicitly; we do not claim audit outcomes we have not received.

Controls in place

Access control
Email/password and Google sign-in via a managed auth provider. Role-based access (owner, office, technician, homeowner) is enforced per workspace. Sessions use short-lived access tokens with refresh rotation.
Data isolation
All workspace data is scoped using database row-level security. Users can only read or modify rows that belong to their workspace and role. Homeowner portal links use unguessable per-property tokens.
Encryption
TLS in transit between browser, application, and infrastructure providers. Encryption at rest is provided by our managed Postgres and object-storage providers.
Personnel & access reviews
Production access is limited to authorized SplashIQ staff. Workspace owners can review, invite, and revoke teammate access from inside the app at any time.
Logging & change management
Application changes are versioned and deployed through an audited build pipeline. Backend errors and security-relevant events are captured for investigation.
Incident response
Suspected incidents are triaged by SplashIQ. Customers affected by a confirmed security incident are notified without undue delay. Vulnerability reports go to hello@splashiq.ai.

Hosting & subprocessors

SplashIQ runs on the Lovable platform with a managed Postgres, Auth, and Storage backend. Outbound email and notifications use vetted providers under data-processing agreements. Optional integrations (QuickBooks, financing requests, marketing email) are opt-in per workspace. Credentials for connected services are stored server-side and never exposed to browsers.

Data handling & retention

Workspace owners can export or delete records from inside the app. Account deletion requests are honored within 30 days. We do not sell personal information. For privacy details, see our Privacy Policy.

Framework alignment (self-assessed)

The controls above map to the following framework areas. This mapping is self-assessed by SplashIQ and is not a substitute for an independent audit report.

  • SOC 2: Security (CC6 logical access, CC7 system operations), Availability (A1), Confidentiality (C1).
  • ISO/IEC 27001 Annex A: A.5 organizational controls, A.8 access control, A.10 cryptography, A.12 operations security, A.13 communications security, A.16 incident management.
  • Contractor due diligence: data isolation, encryption, access management, subprocessor list, incident contact, data export/erasure.

Shared responsibility

SplashIQ provides the platform controls described above. Workspace owners are responsible for managing teammate access, using strong passwords, enabling two-factor authentication where available, and configuring integrations appropriately for their business.

Requesting more detail

Enterprise prospects and contractors performing vendor reviews can request a completed security questionnaire, subprocessor list, or DPA by emailing hello@splashiq.ai. See also our Trust & Security page.

This report reflects current practice and is updated as our controls evolve. It is provided for informational purposes and does not constitute a warranty or an independent certification.