Security & trust at Reality Twin.
How we protect your data, your customers' conversations and your knowledge graph — under Swiss FADP and EU GDPR.
Encryption
TLS 1.3 in transit, AES-256 at rest. Standard, well-understood primitives — no homegrown crypto.
Access control
Every operator account is protected by MFA. Production access is limited to the founder and reviewed regularly.
Per-workspace isolation
Each workspace's data is partitioned at the database row level and enforced by Row-Level Security policies.
EU application, global AI gateway
Database and application workloads run in the European Union (Supabase, Ireland). AI inference is routed through the Lovable AI Gateway, which may forward requests to model providers outside the EU (e.g. US). We disclose this openly rather than claiming full data residency.
Operational integrity
Audit logs, error monitoring, and a small, focused stack we actually understand end-to-end.
Compliance posture
GDPR and Swiss FADP-aligned. SOC 2 and ISO 27001 are on the roadmap — we'll say so honestly when we get there.
Our security commitments.
Application security
All code is reviewed before merge. We use static analysis and dependency scanning on every commit. Production deploys go through automated checks.
Infrastructure & data residency
Application code and the primary database run on managed EU infrastructure (Supabase, Ireland; Cloudflare edge) with daily backups. Reality Twin is a Swiss company and the service is governed by Swiss law; the data itself is stored in the EU. AI inference is routed through the Lovable AI Gateway (ai.gateway.lovable.dev), which may forward prompts to model providers hosted outside the EU, including the United States. Cross-border transfers rely on Standard Contractual Clauses; see the sub-processors page for the full list.
Data isolation
Every workspace's data is partitioned at the database row level and enforced by Row-Level Security policies. We don't share data across workspaces and we don't train shared models on your content.
Incident response
If something breaks or leaks, we notify affected customers directly and quickly. As a small team we don't run a 24/7 SOC — we're honest about that, and we make up for it with rapid response from the founder.
Responsible disclosure
Found a vulnerability? Email hello@realitytwin.io. We respond within one business day and credit researchers publicly with their consent.
What we're working toward
SOC 2 Type I, then Type II, and ISO 27001 — once the customer base and budget make sense. We'll update this page the moment we actually achieve them, not before.