Trust center

Verifiable security, privacy and operational transparency.

This page is maintained by ADmetric AI as the single source of truth for buyers, procurement teams and security reviewers. Every claim links to its corresponding document or live signal.

Note: this trust center summarises currently enabled controls and app-owner practices. It is not an independent certification. Specific audit reports, penetration-test letters and SIG/CAIQ responses are available under NDA via our trust desk.

Compliance programs

SOC 2 Type IIIn progress · Big-Four firm engaged
ISO/IEC 27001Roadmap · target Q4 2026
GDPR / UK-GDPRCompliant · DPA available on request
PSD2 / EMI custodyFunds segregated at regulated EMI partner
PCI-DSSSAQ-A — no cardholder data on our systems

Shared responsibility

Platform

Lovable Cloud + regulated EMI partner — managed encryption, isolation, key custody and money safeguarding.

ADmetric AI

Application logic, role-based access, ledger integrity, vendor due-diligence, incident response, audit logging.

Customer

Workspace settings, member roles, MFA, OAuth scopes, data exports and downstream use of reports.

Report a vulnerability

Email security@admetricai.app. We acknowledge reports within one business day and operate a coordinated disclosure policy.