Trust & Security

How we protect your data

This page is maintained by the AbilityO team to answer common security and privacy questions about AbilityO. It is editable project content, not an independent certification or audit attestation.

Access & authentication

Sign-in uses email + password and Google OAuth. Sessions are issued and validated by our managed authentication provider; passwords are never stored by AbilityO.

Inside a workspace, members are scoped to roles (owner, admin, agent). Sensitive settings — connecting Gmail, rotating provider keys, editing alert destinations — are restricted to owner and admin roles.

Data handling

Customer data is isolated per workspace at the database layer using row-level security. Every query is scoped to the calling user's workspace; cross-tenant reads are denied by default.

Provider API keys and webhook signing secrets are stored with column-level access restrictions and surfaced to the UI only as masked previews (last 4 characters).

Hosting & platform

AbilityO runs on the Lovable platform with a managed Postgres backend. All traffic between your browser and the application is served over HTTPS.

Background workers, scheduled jobs, and webhook endpoints authenticate every request before performing privileged work.

Integrations & subprocessors

AbilityO connects to third-party services (SMM provider panels, Gmail, payment providers, AI model providers) only when a workspace owner enables them, and only with credentials the owner provides. Disabling an integration revokes its access.

A current list of subprocessors and the data shared with each is available on request from the contact below.

Retention & deletion

Workspace owners can delete tickets, orders, and customer records from the application at any time. To request a full workspace deletion or a data export, contact us using the address below.

Security & privacy contact

Report a suspected vulnerability or ask a security/privacy question by emailing security@abilityo.com. We acknowledge reports as soon as we can and follow up with a coordinated fix.

Last reviewed: 2026-07-21. The controls described above reflect what is currently enabled in the application. AbilityO does not claim independent certification (SOC 2, ISO 27001, HIPAA, GDPR adequacy, etc.) on this page — contact us for the latest documentation if your procurement process requires it.