Trust Center
This page is maintained by Embelumy to explain the security, privacy and availability practices that protect your marketplace account data. It describes the controls that are built into the Embelumy platform today.
The information below is provided by Embelumy as app-owned documentation. It is not an independent certification, audit report or legal guarantee.
Security
Embelumy is designed so that marketplace credentials, mailbox tokens and recovery data are never exposed to the browser. The following controls are active for every workspace.
Encryption in transit
All traffic between your browser, our application servers and backend services is encrypted with TLS. OAuth authorization flows, file uploads and API calls never travel over an unencrypted connection.
Encryption at rest
Data stored in our managed database and object storage is encrypted at rest by the cloud provider. Marketplace API tokens, refresh tokens and mailbox credentials receive an additional layer of authenticated encryption before storage.
Secure credential storage
OAuth tokens and API secrets are encrypted with AES-GCM and are only decrypted inside server-side code when performing an authorized request for your account. Credentials are never exposed to, or stored in, the browser.
Row Level Security
Every database record is scoped to the workspace that owns it. Row Level Security policies enforce that users can only read or modify data belonging to their own workspace, even at the database layer.
Server-side API access only
Integration tables that hold tokens, sync runs and health reports are readable and writable only by server-side code using a service identity. Client applications cannot query these tables directly.
Audit logging
Key actions — connecting an integration, importing events, creating cases and generating recovery analyses — are recorded with timestamps and actor information so workspace activity can be reviewed.
Data Protection
Your data is protected by multiple layers of encryption and access control. Marketplace content, imported emails, uploaded documents and AI-generated analyses are all stored in the same secure backend infrastructure.
Encryption layers
- TLS for all browser and API traffic.
- Provider-level encryption at rest for database and storage.
- Application-level AES-GCM encryption for credentials and tokens.
Access control
- Authentication via email/password or Google OAuth.
- Row Level Security policies at the database layer.
- Server-side service identity for integration tables.
AI Processing
Embelumy uses AI to analyze marketplace events, documents and account history. AI outputs are drafts that cite their sources, and they remain under your control.
Inference on request only
Case content is sent to AI model providers only when you trigger an analysis, generate a draft or run a recovery strategy. Providers process the data solely to produce the requested output.
Explainable outputs
Every AI conclusion cites the source documents, emails or events it was derived from. You can inspect the verbatim evidence behind each recommendation before acting on it.
Human in the loop
AI-generated appeals, plans of action and recovery strategies are drafts. A human reviewer must approve, edit and submit them. Embelumy does not submit documents to marketplaces automatically.
Marketplace Integrations
Embelumy connects to marketplaces and mailboxes through OAuth and scoped API access. You control which integrations are active and can revoke them at any time.
OAuth authorization
Marketplace and mailbox connections use OAuth wherever the provider supports it. You authenticate directly with the provider and grant Embelumy a limited, revocable access token.
Mailbox access scope
Email integrations request read-only mailbox access. Embelumy searches for marketplace-related messages, imports matching emails as account events and stores them for analysis.
Marketplace API scope
Marketplace API connections import account health, notifications, listings, inventory and related records required to build your digital twin. Write access is never requested unless a specific recovery workflow explicitly requires it.
Continuous synchronization
Connected integrations sync periodically to keep your account timeline and digital twin current. You can pause or revoke a connection from the Integrations page at any time.
Infrastructure
Embelumy runs on managed cloud infrastructure provided by Lovable Cloud. The underlying platform handles database hosting, authentication, storage, edge functions and deployment. Embelumy adds application-level encryption, access controls and audit logging on top of that foundation.
Hosting
Managed cloud edge platform
Database
PostgreSQL with Row Level Security
Storage
Encrypted object storage
Auth
OAuth + email/password
Availability
The Embelumy application is served from a globally distributed edge network. We do not publish a formal uptime SLA for individual workspaces, but the platform is monitored and designed to recover automatically from routine infrastructure failures.
Application
Edge-deployed, auto-scaling
Database
Managed, automated backups
Status updates
Contact support for incidents
Responsible AI
Embelumy is a decision-support tool, not a replacement for legal or marketplace compliance advice. AI-generated recovery strategies, appeals and plans of action are starting points. You are responsible for reviewing them for accuracy, completeness and compliance with each marketplace's current policies before submission.
What Embelumy does
- Organizes imported marketplace data and documents.
- Generates evidence-backed recovery recommendations.
- Surfaces missing evidence, risks and next best actions.
What you must do
- Verify facts against your own records and marketplace policies.
- Edit drafts before submitting them to a marketplace.
- Consult qualified advisors for legal or regulatory questions.
Privacy
Embelumy processes only the data needed to deliver the service: marketplace account identifiers, imported emails and API records, uploaded documents, user profile information and the analyses generated from them.
Workspace isolation
Each workspace is logically separated. Users cannot access cases, documents or analyses belonging to another workspace unless they have been explicitly invited.
Data deletion
You can delete individual cases, documents and analyses. When you close your account, workspace data is removed after a 30-day grace period, except for limited billing records we are legally required to retain.
No data sale
Embelumy does not sell marketplace content, email data or recovery analyses. Your account data is not used to build products for, or train models for, other customers.
Compliance
Embelumy is built with security and privacy in mind, but we do not claim formal certification under SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS or other frameworks unless explicitly stated in a signed agreement. We support data access, export and deletion requests as described in our Privacy Policy.
Questions or security reports?
For privacy questions, data requests or to report a security concern, contact us at security@embelumy.com. Read the full Privacy Policy and Terms of Service for additional details.