Trust Center

Your leads are your business.We treat them that way.

This page is maintained by Legion AI to answer common security and privacy questions. It describes the controls we operate today, our subprocessors, and how to reach us with security questions.

This is an app-owner-maintained trust page, not an independent certification.

Security controls

The practices and platform capabilities protecting your workspace.

Encryption in transit & at rest

All traffic to Legion AI uses TLS 1.2+. Customer data is stored encrypted at rest on managed cloud infrastructure using AES-256.

Authentication

Email + password with hashed credentials, optional Google SSO, and session tokens rotated on sign-out. Enterprise plans support additional SSO on request.

Row-level access controls

Every record in our database is scoped by workspace and role. Users can only read and write data belonging to their organization.

Managed cloud hosting

Legion AI runs on Lovable Cloud, which provisions Supabase-managed Postgres, storage, and edge functions on hardened cloud infrastructure with automated backups.

Backups & recovery

Daily automated database backups with point-in-time recovery on our production plan. Backups are encrypted and retained for 30 days.

Least-privilege access

Only a small number of Legion engineers have production access, gated by SSO and audit-logged. Access is reviewed quarterly.

Continuous monitoring

Runtime error tracking, uptime monitoring, and automated security scans run against every deploy. Vulnerabilities are triaged within one business day.

Incident response

Documented internal runbook for security incidents. If your data is materially affected, we will notify the primary account contact without undue delay.

Shared responsibility

Security is a partnership. Here's how responsibility splits between Legion AI, our infrastructure provider, and you as a customer.

Lovable Cloud (infrastructure)

  • Hardened database + storage
  • Physical + network security
  • Managed backups

Legion AI (application)

  • App-layer access controls
  • Data encryption + secrets management
  • Vulnerability triage + patching

You (customer)

  • Strong passwords + SSO where available
  • Managing team member access
  • Only sending data you're authorized to process

Subprocessors

Third-party services that process customer data on our behalf.

ProviderPurposeRegion
Lovable Cloud (Supabase)Managed Postgres, auth, storage, edge functionsUS
OpenAI / Anthropic / Google (via Lovable AI Gateway)LLM inference for AI agentsUS
TwilioSMS + programmable voiceUS
ResendTransactional emailUS / EU
StripeBilling & paymentsUS
CloudflareCDN, DNS, DDoS protectionGlobal

Data we collect

  • • Account info (name, email, workspace)
  • • Leads and contacts you import or capture
  • • Conversation transcripts (calls, SMS, email)
  • • Product usage + diagnostics

Retention & deletion

Customer records are retained while your account is active. Deleted records are removed from production within 30 days and from backups within 60 days. Full account deletion can be requested at any time.

Common questions

Do you sell customer data?

No. We never sell, rent, or share customer data with third parties for marketing or advertising. Data is used only to operate and improve the service for you.

Do you train AI models on my data?

No. Prompts and lead data sent to LLM providers through the Lovable AI Gateway are configured to opt out of training. Your data is used to power AI responses in your workspace only.

Where is my data stored?

Production data is stored in US-region managed Postgres on Lovable Cloud (Supabase). Backups are region-locked. Enterprise customers can request additional deployment options.

Can I delete my data?

Yes. You can delete individual records in-app at any time. On account cancellation you can request a full export and permanent deletion by emailing security@thelegionai.com.

Do you have SOC 2 or HIPAA?

Legion AI is not currently SOC 2 or HIPAA certified. We follow the practices described on this page and can provide a security questionnaire on request. Enterprise customers can request a security review before onboarding.

How do I report a vulnerability?

Email security@thelegionai.com with reproduction steps. We acknowledge reports within one business day and will keep you updated on remediation.

Security questions or a report to file?

Reach our security team directly. We acknowledge every report within one business day.