LOOKUPby etechcube
Security

Your data, isolated at the database

For an SMB, letting a vendor hold your financial and operational data is a real decision. Here's exactly how Lookup keeps it separate, private, and traceable — in plain terms.

The isolation model

Separation the application layer can't accidentally undo

Most multi-tenant apps keep companies apart with a filter in application code — one forgotten clause and one company can see another's data. Lookup enforces separation in Postgres itself with row-level security: a query running as one tenant physically cannot return another tenant's rows, regardless of what the application code asks for.

tenant isolation · enforced in the database
Company Asees only Company A rows
Company Bsees only Company B rows
A query for Areturns 0 rows of B — always
Enforced by Postgres row-level security policies, tested by an isolation suite that must pass on every release.
How we handle your data

The practices behind the promise

Isolation at the database

Row-level security policies enforce tenant separation in Postgres itself — not just a WHERE clause in application code that a bug could forget.

Every number is auditable

Drill-through from any KPI to the exact source rows means there's no black box: what the dashboard shows, you can always trace back.

Branch & plant scoping

Within a company, a manager can be limited to their branch or plant — least-privilege access layered on top of tenant isolation.

Roles, not free-for-all

Owner, analyst and viewer roles gate who can configure, who can see source rows, and who can only read dashboards.

Your data stays yours

You own the business data you provide. We use it to run your dashboards — not to train anything, and never sold.

Anonymised benchmarking only

Where peer benchmarking is offered, it uses anonymised and aggregated cohort data. One company's rows are never exposed to another.

Straight talk

We won't claim certifications we don't hold. As a young product we're building our formal compliance posture in step with our customers' needs. What we can show you today is the architecture, the isolation tests, and honest answers to any question you put to us — and we'd rather earn trust that way than with a badge we haven't verified.

Data lifecycle

What happens to your data

You upload or push only the business data needed for your dashboards
It's mapped into a canonical model and isolated to your tenant
It's retained while your account is active, then deleted or anonymised
You can request access, correction or deletion at any time

See the Privacy Policy for the full detail.

Get started

Have a security question before you share data?

Talk to us — we'll answer plainly, and show you the architecture if you want it.