As of 24 June 2026
Operational metrics
Pilot-stage numbers, published honestly. We would rather say “not measured” than show a green tile we cannot defend. Linked context lives in the Trust Centre and the Security Roadmap.
Posture
No paying tenant has gone live yet. Metrics below reflect platform behaviour during build + invited preview, not production load.
First paid pilot is the trigger for the MFA-mandatory cutover (see Security Roadmap).
Reliability
External uptime monitoring is on the trigger-tied roadmap (lands with first paid pilot). Until then we publish 'not measured' rather than a fabricated 100 %.
Honesty over theatre — no synthetic SLA until we actually monitor it.
Server-bundle crash from a top-level CommonJS import in a route module took every public URL to HTTP 500. Root cause and fix are in the build log; lazy-import rule added to Security Memory to prevent recurrence.
Security
Tracked against the Aikido continuous scan and the in-Lovable security scan; both clean of critical findings as of the date above.
No incident has affected customer data — there is no customer data in production yet.
Three Wiz/Aikido-class findings remediated since 18 June 2026, each within the same working day as detection.
Continuous automated scanning (Aikido SAST, SCA, secrets, IaC, surface) runs against every build. An independent third-party human pen test is deferred until first paying pilot or a named prospect request — pre-revenue spend on a report that ages out in 12 months is poor value. Decision and triggers logged at .lovable/pentest/decisions.md.
How this page is maintained. Every metric here maps to a source we can show an auditor: the build log, the incident register, the Aikido scan, or the pen-test report. When a number changes we update this page and the date stamp at the top — we do not retroactively edit history.