Memoir Hive

Trust

Trust & Security

This page is maintained by Memoir Hive to answer common security and hosting questions.

Hosting and infrastructure

Memoir Hive runs on Amazon Web Services (AWS). AWS is the only cloud infrastructure provider we use to host, store, and back up platform data.

We do not use Google Cloud, Microsoft Azure, Alibaba, Tencent, Oracle Cloud, Heroku, DigitalOcean, or any other listed infrastructure provider to store Memoir Hive user data. Our database and object storage are provided through the Lovable Cloud platform, which is backed by AWS infrastructure.

Security practices

  • Encryption in transit: all traffic between your browser and Memoir Hive is protected by TLS.
  • Encryption at rest: data stored in our database and storage buckets is encrypted at rest by AWS.
  • Row-level security: database access is enforced at the row level, so users can only read and modify their own records.
  • Secrets vault: API keys, tokens, and other secrets are held in a restricted vault and never exposed to the browser.
  • Limited access: administrative access is limited to a small number of authorised staff.
  • Backups: public database tables are backed up weekly into a private AWS storage bucket.

No system is perfectly secure. Keep your sign-in credentials safe and tell us promptly if you suspect unauthorised access.

Vulnerability management and patching

We maintain a defined and repeatable process for identifying, prioritising and applying security patches to the software behind Memoir Hive.

  • Identification: automated dependency vulnerability scanning of third-party packages, static application security testing of our source code, and automated database access-control scanning on every backend change. We also monitor security advisories from our hosting and backend providers.
  • Prioritisation: each issue is rated by CVSS severity and adjusted for real-world exploitability. Targets are 7 days for critical, 30 days for high, 90 days for medium, and routine maintenance for low.
  • Application: patches ship through our standard build and release pipeline. Every change is built and type-checked before deployment, releases are versioned and can be rolled back, and scans are re-run afterwards to confirm the issue is resolved.
  • Underlying infrastructure: we do not operate our own servers or operating systems. Operating-system, hypervisor and network-layer patching is handled by AWS and our managed backend provider.

If you believe you have found a security vulnerability, please contact us before disclosing it publicly so we can investigate and fix it.

Backend vulnerability testing

We run structured backend vulnerability testing against the Memoir Hive web application, its APIs, and the database access layer. The goal is to find and fix security weaknesses before they can be exploited.

  • Scope: testing covers the public-facing website, authenticated API routes, server-side business logic, and the database access layer. It does not include third-party infrastructure or social-engineering exercises.
  • Methods: we use automated dynamic application security testing (DAST) and automated web vulnerability scanning to identify common issues such as injection flaws, broken access control, and insecure configuration.
  • Frequency: vulnerability tests are run at least once every 12 months, and sooner after any major infrastructure or authentication change.
  • Triage and remediation: findings are rated by severity and tracked to completion. Critical issues are fixed within 7 days, high-severity issues within 30 days, and medium issues within 90 days.
  • Validation: we re-test after fixes to confirm vulnerabilities are resolved and do not reappear in the same form.

Detailed methodology and scope are documented in the Memoir Hive backend vulnerability testing policy.

Subprocessors and integrations

We share data only with the processors and integrations we need to run the Service. Each processor is bound by a data-processing agreement that limits use of your data to the service they perform for us.

ProviderPurpose
Amazon Web Services (AWS)Cloud hosting, database storage, backups, and object storage
SupabaseManaged database, authentication, and storage services
StripePayment processing
TwilioSMS delivery
Email delivery providersTransactional and scheduled email delivery
AI model providersBiography drafting, AI Presence, and media generation
Google MapsMap display when you add location pins to gallery items
Meta (Facebook / Instagram)Optional social account connections and photo import
LinkedInOptional company page posting

When you choose to publish content to the open web, the content you mark as public is, by design, visible to anyone with the link.

Data deletion and privacy

You can request deletion of your personal data at any time. For details about deleting Facebook-connected data, see the User Data Policy and the Data Deletion Status page.

For security or privacy questions, email legal@memoirhive.com. We respond to verified requests within 30 days.

Platform fact

Memoir Hive is built on the Lovable platform. Lovable Cloud provides the managed backend, authentication, and storage services that Memoir Hive uses. The underlying infrastructure for those services is AWS.