Security

Last updated: July 28, 2026

This page is maintained by MS Solutions to answer common security questions about Easyexports. It describes controls that are currently in place. It is not a certification and does not create additional contractual commitments beyond your subscription agreement.

Data in transit and at rest

  • All traffic between browsers and Easyexports is served over HTTPS (TLS).
  • Application data is stored in a managed Postgres database with encryption at rest provided by the hosting platform.
  • Passwords are never stored in plaintext; authentication is delegated to the managed auth provider which stores salted hashes.

Authentication and access control

  • Email/password and Google sign-in are supported.
  • Row-Level Security (RLS) is enabled on customer-data tables so users only see their own records.
  • Administrative roles are stored in a dedicated table and checked via a security-definer function — never trusted from the client.

Hosting and platform

  • Easyexports runs on the Lovable platform, which provides managed hosting, database, authentication and edge functions.
  • Server-side code executes in an isolated serverless runtime; secrets are injected at runtime and are not exposed to the browser.
  • Publishable/anonymous API keys used in the browser have no privileged access and are scoped by RLS.

Sub-processors

We use the following sub-processor to deliver the service:

  • Lovable — application hosting, managed database, authentication, storage, edge functions and AI gateway.

If additional sub-processors are added, this list will be updated before they begin processing customer data.

People and access

  • Only authorised MS Solutions personnel have access to production systems, on a least-privilege basis and only to operate or support the service.
  • Team members are bound by written confidentiality obligations.

Incident response and reporting

If we become aware of a security incident affecting customer data, we will investigate, take reasonable steps to contain and remediate it, and notify affected customers without undue delay. Report suspected vulnerabilities or incidents to support@exporteasy.online. Please do not publicly disclose issues until we have had a reasonable opportunity to respond.

Shared responsibility

MS Solutions maintains the security of the platform and its configuration. Customers are responsible for choosing strong passwords, protecting their account credentials, controlling who they invite into their workspace, and ensuring the data they upload is lawful for them to process.

Compliance posture

Easyexports does not currently hold formal certifications such as SOC 2 or ISO 27001. We describe the controls that are enabled today on this page; we do not claim regulatory compliance beyond that. For DPA questions see the Data Processing Agreement.