SSMARTY.CC
00Index / Security

Security at SMARTY.cc.

SMARTY.cc runs on a managed cloud platform and follows a shared-responsibility model. Platform controls come from the underlying infrastructure. Application controls, data handling, and engineering review remain the responsibility of SMARTY.cc and the customer organization.

Key takeaways
  • This page is maintained by SMARTY.cc and is not an independent certification
  • Shared responsibility between platform, SMARTY.cc, and the customer
  • Report vulnerabilities to hi@smarty.cc
  • Specific controls will be confirmed as the product moves toward general availability
01Editable notice

This page is maintained by SMARTY.cc to answer common questions about how the product handles security. It describes current intent and app-visible controls. It is not a certification, audit report, or legal guarantee.

02How does SMARTY.cc protect engineering data?

A shared model.

Engineering data is protected under a shared-responsibility model across three layers. Each layer owns a distinct set of controls, and the whole only works when all three are honored.

  • Platform. The underlying managed cloud provides network isolation, managed databases, authentication primitives, and the runtime for server-side code.
  • SMARTY.cc. Access control inside the application, how prompts and workflow data are handled, and how engineering review is enforced before automation is applied.
  • Customer. Account hygiene, who is invited into a workspace, and the engineering judgment applied to any SMARTY.cc output before it is committed to a production model.
03Where is customer data processed?

SMARTY.cc is built on Lovable Cloud, which provides the managed database, authentication, storage, and serverless functions the application runs on. Those platform capabilities include transport encryption between the browser and the platform and role-scoped access to the database. Regional processing details for a specific deployment are confirmed with the SMARTY.cc team under the written customer agreement; additional platform detail is available from Lovable Cloud documentation.

04How are product actions logged and reviewed?

SMARTY.cc commits to audit logging of SMARTY.cc-directed actions taken inside HyperMesh, with engineer review as the gate before any automation is applied. Every applied change is attributable to a human engineer who approved it. Additional application controls include account roles for access separation, per-customer workspace isolation, and encryption at rest for application-owned data via the Lovable Cloud platform. Exact audit-log scope and retention for a specific deployment are set in the written customer agreement.

05Does SMARTY.cc retain prompts, models, or uploaded files?

Prompts, engineering context, and generated workflow drafts pass through model providers used by SMARTY.cc. Specific retention windows and data-handling terms for those providers, and for application-owned data, are confirmed under a written agreement with each customer rather than committed to on this page.

SMARTY.cc does not certify simulation results and does not replace engineering review. Generated automation should be treated as a draft until validated against a known baseline.

06Can SMARTY.cc run on premises or in an air-gapped environment?

Deployment options, including on-premises or air-gapped configurations, are confirmed directly with the SMARTY.cc team for your specific environment and are not committed to on this page. See Pricing for how deployment constraints factor into a commercial conversation.

07How do I report a security concern?

If you believe you have found a security issue in SMARTY.cc, contact hi@smarty.cc with a description of the issue and reproduction steps. Please do not test against production customer data or attempt to access accounts that are not your own.

Related reading: Privacy Policy, Acceptable Use Policy.

08Engineering safety

What SMARTY.cc does not do.

SMARTY.cc is an assistive layer. Engineering responsibility for model correctness, solver setup, and result interpretation stays with qualified engineers.

  • B.01

    SMARTY.cc does not replace HyperMesh.

  • B.02

    SMARTY.cc does not replace a solver.

  • B.03

    SMARTY.cc does not certify results.

  • B.04

    Qualified engineers must validate all model changes and solver inputs.

09Security questions

Talk to us about your deployment.

Security expectations vary by engineering organization. If you need specifics for a HyperMesh pilot, request a direct conversation and we will answer against your actual environment rather than a generic checklist.