Trust & safety

Security

Last updated: [PLACEHOLDER — publish date]

This page is maintained by the UniDoodle team to describe the security controls in place today. It is not an independent certification.

Infrastructure

UniDoodle runs on Lovable Cloud with data stored in a managed Postgres database. Traffic is encrypted in transit with TLS. Backups and point-in-time recovery are managed by the platform.

Access controls

  • Row-level security policies on every user-owned table.
  • Role separation between students, teachers and organisations.
  • Server-side authentication with per-request middleware for privileged operations.
  • Least-privilege service credentials for background jobs.

Payments

All card payments are handled by Stripe (PCI-DSS Level 1). Webhook signatures are verified before any subscription state change.

Reporting a vulnerability

If you believe you have found a security issue, please email security@unidoodle.com. Please give us a reasonable time to remediate before public disclosure. [PLACEHOLDER — full responsible disclosure policy].

This is a working draft. Items marked [PLACEHOLDER] must be reviewed and completed by the UniDoodle team (and its legal advisers) before general availability.