This page documents the security safeguards currently present in the LifeLeveled application and its hosting infrastructure. Only verified controls are listed under "Currently Implemented." Planned improvements are labeled as such.
Important: LifeLeveled has not completed independent security audits, penetration tests, or formal certifications. The safeguards listed below are those currently provided by the application and its hosting infrastructure. They are self-assessed and have not been independently verified.
Currently Implemented Safeguards
Encryption & Transport
- HTTPS encryption in transit. All traffic to and from the application is encrypted via HTTPS, provided by the hosting infrastructure.
Authentication
- OAuth 2.0 authentication. Users can authenticate via Google, Microsoft, Apple, and Facebook using OAuth 2.0.
- Email/password authentication. Credential storage is managed by the platform's authentication infrastructure; passwords are not stored in plaintext in the application database.
Access Control
- Row-level security (RLS). All user data entities enforce database-level access control — users can only read, create, update, or delete their own records.
- Admin-only operations. User management, data deletion, and institutional operations are restricted to admin role users via RLS rules.
- Service-role separation. Backend functions use a service role for elevated operations, separate from end-user authentication context.
Payment Security
- Stripe payment processing. All payments are processed through Stripe. Card data is handled by Stripe's PCI-compliant infrastructure and is never stored in the LifeLeveled application or database.
AI Feature Governance
- Feature flags for AI capabilities. AI features (Coach, Camera Coach, Roleplay, Driver AI, Support Agent) can be enabled or disabled by admin users through a feature flag system, providing an operational kill switch.
Planned Security Improvements
The following improvements are on the product roadmap but are not yet operational:
- Formal penetration testing by a qualified third party
- Documented incident response procedures with defined timelines
- Security monitoring and alerting for anomalous activity
- Regular security audits against industry frameworks
- Formal data encryption at rest verification
Planned improvements are presented as roadmap items, not operational claims. They should not be relied upon for current security determinations.
What Is Not Claimed
To avoid overstating security posture, LifeLeveled explicitly does not claim:
- Independent security certifications (e.g., SOC 2, ISO 27001)
- Completed penetration testing
- Specific encryption standards for data at rest
- Defined breach notification timelines (these are set in institutional contracts)
- Specific data center locations or geographic data residency guarantees
- Formal incident response team or 24/7 security operations center