Trust Center

This page is maintained by Embelumy to explain the security, privacy and availability practices that protect your marketplace account data. It describes the controls that are built into the Embelumy platform today.

The information below is provided by Embelumy as app-owned documentation. It is not an independent certification, audit report or legal guarantee.

Security

Embelumy is designed so that marketplace credentials, mailbox tokens and recovery data are never exposed to the browser. The following controls are active for every workspace.

Encryption in transit

All traffic between your browser, our application servers and backend services is encrypted with TLS. OAuth authorization flows, file uploads and API calls never travel over an unencrypted connection.

Encryption at rest

Data stored in our managed database and object storage is encrypted at rest by the cloud provider. Marketplace API tokens, refresh tokens and mailbox credentials receive an additional layer of authenticated encryption before storage.

Secure credential storage

OAuth tokens and API secrets are encrypted with AES-GCM and are only decrypted inside server-side code when performing an authorized request for your account. Credentials are never exposed to, or stored in, the browser.

Row Level Security

Every database record is scoped to the workspace that owns it. Row Level Security policies enforce that users can only read or modify data belonging to their own workspace, even at the database layer.

Server-side API access only

Integration tables that hold tokens, sync runs and health reports are readable and writable only by server-side code using a service identity. Client applications cannot query these tables directly.

Audit logging

Key actions — connecting an integration, importing events, creating cases and generating recovery analyses — are recorded with timestamps and actor information so workspace activity can be reviewed.

Data Protection

Your data is protected by multiple layers of encryption and access control. Marketplace content, imported emails, uploaded documents and AI-generated analyses are all stored in the same secure backend infrastructure.

Encryption layers

  • TLS for all browser and API traffic.
  • Provider-level encryption at rest for database and storage.
  • Application-level AES-GCM encryption for credentials and tokens.

Access control

  • Authentication via email/password or Google OAuth.
  • Row Level Security policies at the database layer.
  • Server-side service identity for integration tables.

AI Processing

Embelumy uses AI to analyze marketplace events, documents and account history. AI outputs are drafts that cite their sources, and they remain under your control.

Inference on request only

Case content is sent to AI model providers only when you trigger an analysis, generate a draft or run a recovery strategy. Providers process the data solely to produce the requested output.

Explainable outputs

Every AI conclusion cites the source documents, emails or events it was derived from. You can inspect the verbatim evidence behind each recommendation before acting on it.

Human in the loop

AI-generated appeals, plans of action and recovery strategies are drafts. A human reviewer must approve, edit and submit them. Embelumy does not submit documents to marketplaces automatically.

Marketplace Integrations

Embelumy connects to marketplaces and mailboxes through OAuth and scoped API access. You control which integrations are active and can revoke them at any time.

OAuth authorization

Marketplace and mailbox connections use OAuth wherever the provider supports it. You authenticate directly with the provider and grant Embelumy a limited, revocable access token.

Mailbox access scope

Email integrations request read-only mailbox access. Embelumy searches for marketplace-related messages, imports matching emails as account events and stores them for analysis.

Marketplace API scope

Marketplace API connections import account health, notifications, listings, inventory and related records required to build your digital twin. Write access is never requested unless a specific recovery workflow explicitly requires it.

Continuous synchronization

Connected integrations sync periodically to keep your account timeline and digital twin current. You can pause or revoke a connection from the Integrations page at any time.

Infrastructure

Embelumy runs on managed cloud infrastructure provided by Lovable Cloud. The underlying platform handles database hosting, authentication, storage, edge functions and deployment. Embelumy adds application-level encryption, access controls and audit logging on top of that foundation.

Hosting

Managed cloud edge platform

Database

PostgreSQL with Row Level Security

Storage

Encrypted object storage

Auth

OAuth + email/password

Availability

The Embelumy application is served from a globally distributed edge network. We do not publish a formal uptime SLA for individual workspaces, but the platform is monitored and designed to recover automatically from routine infrastructure failures.

Application

Edge-deployed, auto-scaling

Database

Managed, automated backups

Status updates

Contact support for incidents

Responsible AI

Embelumy is a decision-support tool, not a replacement for legal or marketplace compliance advice. AI-generated recovery strategies, appeals and plans of action are starting points. You are responsible for reviewing them for accuracy, completeness and compliance with each marketplace's current policies before submission.

What Embelumy does

  • Organizes imported marketplace data and documents.
  • Generates evidence-backed recovery recommendations.
  • Surfaces missing evidence, risks and next best actions.

What you must do

  • Verify facts against your own records and marketplace policies.
  • Edit drafts before submitting them to a marketplace.
  • Consult qualified advisors for legal or regulatory questions.

Privacy

Embelumy processes only the data needed to deliver the service: marketplace account identifiers, imported emails and API records, uploaded documents, user profile information and the analyses generated from them.

Workspace isolation

Each workspace is logically separated. Users cannot access cases, documents or analyses belonging to another workspace unless they have been explicitly invited.

Data deletion

You can delete individual cases, documents and analyses. When you close your account, workspace data is removed after a 30-day grace period, except for limited billing records we are legally required to retain.

No data sale

Embelumy does not sell marketplace content, email data or recovery analyses. Your account data is not used to build products for, or train models for, other customers.

Compliance

Embelumy is built with security and privacy in mind, but we do not claim formal certification under SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS or other frameworks unless explicitly stated in a signed agreement. We support data access, export and deletion requests as described in our Privacy Policy.

Questions or security reports?

For privacy questions, data requests or to report a security concern, contact us at security@embelumy.com. Read the full Privacy Policy and Terms of Service for additional details.