Stripe processes payments
Payments flow through Stripe, a licensed money transmitter. AirInk never holds customer funds.
Maintained by AirInk and describing what is in place today. Not an audit, not a certification.
Maintained by AirInk and current as of this deployment.
AirInk runs on Lovable, which publishes a Trust Center for this deployment. It is generated and maintained by Lovable, not by AirInk, and reports platform-level security evidence for airink.ai.
The evidence export is available to signed-in users. It bundles the published JSON evidence, retrieved server-side, with the AirInk control list above.
AirInk owns the platform, its authentication, its Stripe integration, and the controls above. You own the accuracy of your contract terms, your milestone confirmations, and the security of your own devices.
Report suspected vulnerabilities to security@airink.ai. Include the affected URL or endpoint, steps to reproduce, and the impact you believe is possible. We acknowledge reports within 3 business days and keep you informed until the issue is resolved.
We support good-faith security research: do not access, modify, or delete data that is not yours, do not degrade the service for others, and give us a reasonable window to fix the issue before any public disclosure. Research conducted within those bounds will not be met with legal action by AirInk. A machine-readable version of this policy lives at /.well-known/security.txt.
AirInk maintains a written incident response plan covering triage, containment, remediation, and notification. If an incident affects your data, we will notify you by email without unreasonable delay, consistent with applicable state breach-notification laws, and tell you what happened, what data was involved, and what we are doing about it. Payment card and bank credentials are held by Stripe, not AirInk, which limits what any AirInk-side incident can expose.
Introductory pricing: the rate rises once the founding cohort closes. Yours locks for life.