Security
Last updated 10 June 2026
1. Data encryption
All data transmitted between your browser and Tova is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256. Backups are encrypted with the same standard.
2. Access controls
Access to production data is restricted to authorised M28 Ventures BV personnel and the AI agents operating under human governance. All access is authenticated and logged. Employees and agents undergo security training and operate under confidentiality agreements.
3. Infrastructure security
Tova is hosted on Base44's EU infrastructure, which undergoes regular security assessments. Our cloud providers maintain ISO 27001 and SOC 2 Type II certifications. We follow a security-by-design approach and conduct periodic security reviews of our application code.
4. Payment security
We do not store payment card details. All payment processing is handled by Stripe, which is PCI DSS Level 1 compliant — the highest level of payment security certification.
5. Incident response
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected users without undue delay, as required by GDPR Article 33–34.
6. Responsible disclosure
If you discover a security vulnerability in Tova, please report it to us at hello@tovameals.com before public disclosure. Include a description of the vulnerability, steps to reproduce, and potential impact. We will acknowledge receipt within 2 business days and aim to resolve valid reports within 30 days. We ask that you do not access, modify, or delete data beyond what is necessary to demonstrate the vulnerability.
7. Contact
Security disclosures: hello@tovameals.com