Security · Trust

    How we handle your data.

    Plain answers to the questions a security-conscious buyer actually asks. No buzzwords, no certifications we haven't earned, no hand-waving.

    01

    Where your data lives

    Lembra runs on Supabase, hosted in AWS Singapore (ap-southeast-1). All employee and order data is row-level-security scoped. Your team's data is logically isolated from every other company's by Postgres RLS policies, enforced at the database layer.

    • Database: Supabase Postgres in AWS ap-southeast-1 (Singapore)
    • Row-level-security on every table that holds company data
    • Daily automated backups, 7-day point-in-time recovery
    • All connections TLS 1.2+; no plaintext data in transit
    02

    Payment security

    We never see your card. Payment details go directly to Stripe via their hosted checkout. Lembra's servers only receive a session reference. Stripe is PCI-DSS Level 1 certified.

    • Stripe-hosted checkout: card numbers never touch our servers
    • Stripe is PCI-DSS Level 1 certified (highest tier)
    • Webhook events signed and verified server-side
    • Refunds and disputes routed through Stripe; we hold no balances
    03

    Employee data we collect (and don't)

    Lembra needs the minimum to do its job: name, birthday or work-anniversary date, dietary preferences, and a delivery address. That's it. We don't ask for tax info, salary, performance data, or anything else HR systems track.

    • Collected: name, celebration date, dietary preferences, delivery address
    • Never collected: salary, tax info, performance data, manager notes
    • Employees can be removed by an admin at any time. Their data is hard-deleted within 30 days.
    • Recipients of gifts get one notification email; we don't add them to marketing
    04

    Account security

    Authentication runs through Supabase Auth. Passwords are hashed with bcrypt, sessions use signed JWTs with 1-hour rotation, and we never store reset tokens in plaintext.

    • Supabase Auth (bcrypt password hashing)
    • JWT sessions, 1-hour expiry with refresh-token rotation
    • Password resets via signed time-limited links
    • Magic-link sign-in supported; passwordless accounts never set a password
    • Workspace admins can invite + remove team members at any time
    05

    Subprocessors we depend on

    Lembra is composed of a few well-known services. Each one has its own security posture you can read.

    • Supabase: database, auth, and storage (AWS Singapore, ap-southeast-1)
    • Stripe: payment processing (PCI-DSS Level 1)
    • Resend: transactional email (US-region)
    • Anthropic: concierge chat LLM (data not retained for training per Anthropic's API terms)
    • Sentry: error tracking (US-region; PII scrubbed via beforeSend hook)
    • Lovable: frontend hosting (CDN edge)
    Roadmap · Honest about what's not done

    What we're working towards.

    Lembra is early-stage. We don't carry SOC 2 yet. That's a meaningful 12-18 month commitment we haven't started. If your team requires a formal certification before sign-up, tell us what you need and we'll either point you to where we are on the journey or pause the conversation honestly.

    • SOC 2 Type II: not started, planning a 2026 H2 review
    • SAML / SSO for enterprise: on the roadmap, available on request when we get there
    • Customer-managed encryption keys: not in scope for now, to revisit as enterprise demand grows

    Security questions?

    Email security@lembra.com.au and we'll answer within one business day.

    Ready when you are.

    Brief our concierge with your first celebration. Or read the privacy policy + terms in full first.