
Trust & Security
This page is maintained by Vintara CPA to answer common security and privacy questions about the affiliate platform. It describes controls that are currently enabled in the app and is not an independent certification or audit.
Access & authentication
- Affiliate and admin sign-in uses email and password against the Vintara CPA managed authentication backend.
- New affiliate registrations start in a pending state and require manual review before any earnings or tracking links become active.
- Roles are stored in a dedicated server-side table and checked on every protected request. Roles cannot be self-assigned at signup.
- Sensitive profile fields (status, email, affiliate ID, registration date, smartlink eligibility) are read-only to the affiliate and can only be changed by an administrator.
Data scoping
- Every affiliate-facing database table is protected by row-level security so an affiliate can only read and write their own clicks, conversions, balance entries, and notifications.
- Commercially sensitive offer data (advertiser payouts, advertiser destination links, internal notes) is never returned to affiliate sessions.
- Conversions are written only by the verified server-side postback endpoint and cannot be created or modified from the browser.
Platform & hosting
- Vintara CPA runs on the Lovable platform with a managed Postgres database and an edge server runtime. Traffic to the app is served over HTTPS.
- Privileged operations execute server-side only. Service credentials are stored as managed secrets and are never shipped to the browser bundle.
Lovable platform capabilities described here are factual statements about enabled features, not a certification of Vintara CPA by Lovable.
Shared responsibility
- Lovable operates the underlying hosting, database, and authentication infrastructure.
- Vintara CPA is responsible for affiliate onboarding, offer configuration, payout decisions, and any data handling specific to its business.
- Affiliates are responsible for keeping their login credentials confidential and only sending traffic that complies with the offer's rules.
Reporting a security concern
If you believe you have found a security or privacy issue, please contact Vintara CPA through the affiliate support channels listed inside the platform. Include enough detail to reproduce the issue and please do not exploit it against real affiliates or live offer data.
This page is editable project content maintained by Vintara CPA. It is not a Lovable-issued certification and does not constitute a legal commitment.
© 2026 Vintara CPA