Security

Security & trust at Reality Twin.

How we protect your data, your customers' conversations and your knowledge graph — under Swiss FADP and EU GDPR.

Encryption

TLS 1.3 in transit, AES-256 at rest. Standard, well-understood primitives — no homegrown crypto.

Access control

Every operator account is protected by MFA. Production access is limited to the founder and reviewed regularly.

Per-workspace isolation

Each workspace's data is partitioned at the database row level and enforced by Row-Level Security policies.

EU application, global AI gateway

Database and application workloads run in the European Union (Supabase, Ireland). AI inference is routed through the Lovable AI Gateway, which may forward requests to model providers outside the EU (e.g. US). We disclose this openly rather than claiming full data residency.

Operational integrity

Audit logs, error monitoring, and a small, focused stack we actually understand end-to-end.

Compliance posture

GDPR and Swiss FADP-aligned. SOC 2 and ISO 27001 are on the roadmap — we'll say so honestly when we get there.

Program

Our security commitments.

Application security

All code is reviewed before merge. We use static analysis and dependency scanning on every commit. Production deploys go through automated checks.

Infrastructure & data residency

Application code and the primary database run on managed EU infrastructure (Supabase, Ireland; Cloudflare edge) with daily backups. Reality Twin is a Swiss company and the service is governed by Swiss law; the data itself is stored in the EU. AI inference is routed through the Lovable AI Gateway (ai.gateway.lovable.dev), which may forward prompts to model providers hosted outside the EU, including the United States. Cross-border transfers rely on Standard Contractual Clauses; see the sub-processors page for the full list.

Data isolation

Every workspace's data is partitioned at the database row level and enforced by Row-Level Security policies. We don't share data across workspaces and we don't train shared models on your content.

Incident response

If something breaks or leaks, we notify affected customers directly and quickly. As a small team we don't run a 24/7 SOC — we're honest about that, and we make up for it with rapid response from the founder.

Responsible disclosure

Found a vulnerability? Email hello@realitytwin.io. We respond within one business day and credit researchers publicly with their consent.

What we're working toward

SOC 2 Type I, then Type II, and ISO 27001 — once the customer base and budget make sense. We'll update this page the moment we actually achieve them, not before.