> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lovable.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Lovable for Enterprise

> Build and ship AI-generated apps at organizational scale with the security, governance, identity, and compliance controls your security team expects.

Lovable Enterprise plan gives organizations a governed environment to build AI-generated applications at scale, with centralized identity, granular access controls, workspace-wide security oversight, scheduled Deep scans, audit logs, regional code hosting, EU inference for AI model requests, and a dedicated commercial relationship.

Features marked **Business and Enterprise** are also available on the self-serve Business plan. Features marked **Enterprise only** require a contract.

<Card title="Talk to our sales team" icon="arrow-right" horizontal href="https://lovable.dev/enterprise">
  Tell us about your team's identity provider, compliance requirements, and use case. We'll set up an Enterprise workspace and walk through migration from your existing plan if needed.
</Card>

## At a glance

| Area | Covered by |
| :- | :- |
| **Identity** | SSO (OIDC and SAML 2.0), SCIM, 2FA, workspace groups, verified-domain provisioning |
| **Governance** | Roles, restricted projects, invitation controls, project transfer controls, publishing controls, app login methods, training-data exclusion by default |
| **Security** | Quick scan, Deep scan, scheduled Deep scans, Security center, sensitive data scanning, chat send protection, Aikido, Wiz |
| **Auditability** | Audit logs retained for 13 weeks (approximately 90 days), JSONL exports, and SIEM forwarding via account team |
| **Adoption** | Insights: visits, active apps, active builders, and connections added across the workspace, with top apps, top builders, adoption by department for SCIM workspaces, and CSV export |
| **Data and code control** | GitHub Enterprise Cloud (data residency), GitHub Enterprise Server, GitLab, Bitbucket, external hosting, build secrets, EU inference |
| **Compliance** | SOC 2 Type II, ISO 27001:2022, AIUC-1, GDPR, DPA, sub-processors |

## Who Enterprise is for

Enterprise workspaces are designed for organizations that need to:

* Centralize how the whole team logs in and gets provisioned
* Restrict who can build, publish, and share apps externally
* Detect and block sensitive data in project chat messages before it leaves the workspace
* Schedule recurring security scans across every project automatically
* Keep an auditable record of every change across every project
* Keep code data inside a specific GitHub region or on self-hosted infrastructure
* Keep AI model requests on model endpoints in the European Union
* Standardize design, components, and engineering knowledge across every project
* Set spend, security, and data-handling policies once and apply them everywhere
* Connect AI-built apps directly to existing data warehouses and enterprise systems

## What Enterprise adds beyond Business

Business already includes workspace SSO, groups, the Security center, Insights, App login methods, design templates, branded app URLs, restricted projects, training-data exclusion by default, and workspace-level connector controls. Enterprise adds:

* **Identity and provisioning**, SCIM provisioning, SCIM-managed member filtering, SCIM precedence over just-in-time (JIT) provisioning, group-to-role mappings, and a self-serve SSO just-in-time (JIT) provisioning toggle.
* **Governance**, restrict workspace invitations, project transfer controls, require workspace editor role for editing, custom workspace member caps, and workspace deletion through your account team.
* **Security and data protection**, PII findings in Security insights, scheduled Deep security scans, sensitive data scanning, chat send protection, block publishing with PII, the opt-in to extended-retention models, and EU inference.
* **Publishing controls**, restrict who can publish externally and disable public preview links.
* **Code and infrastructure**, GitHub Enterprise Cloud with data residency, GitHub Enterprise Server, and build secrets.
* **Team enablement and support**, design systems from an existing npm package, audit logs, SIEM forwarding via account team, dedicated account team, priority support, and custom onboarding.

## Identity and access

Centralize how your team authenticates and gets access to Lovable.

<CardGroup cols={2}>
  <Card title="Workspace SSO" icon="shield-keyhole" href="/features/business/sso">
    **Business and Enterprise.** Okta, Auth0, Microsoft Entra ID, or any OIDC or SAML 2.0 provider. Enforce SSO with 8h, 24h, 48h, or 7d session duration. JIT-provision users at a default role.
  </Card>

  <Card title="SCIM provisioning" icon="users-cog" href="/features/business/scim">
    **Enterprise only.** Automated user and group lifecycle from your identity provider. Group-to-role mappings, API-key rotation, SCIM precedence over JIT. SCIM-managed filter on the People tab.
  </Card>

  <Card title="Two-factor authentication" icon="lock" href="/introduction/two-factor-authentication-2-fa">
    **All plans.** Authenticator-app or SMS 2FA on top of any login method, including SSO. Configured per account. Enterprise workspaces can [require 2FA](/features/privacy-and-security-settings#require-two-factor-authentication) for all members.
  </Card>

  <Card title="Workspace groups" icon="users" href="/features/groups">
    **Business and Enterprise.** Share projects, folders, and published-app access by group. SCIM groups sync from your identity provider.
  </Card>

  <Card title="Verified-domain provisioning" icon="check-double" href="/features/workspace-identity#user-provisioning">
    **Business and Enterprise.** Auto-add anyone signing up with a verified company email, or bulk-provision every existing user on a domain in one action.
  </Card>

  <Card title="Reuse Lovable workspace identity in apps" icon="id-badge" href="/features/lovable-workspace-identity-reuse">
    **Business and Enterprise.** Internal tools recognize the logged-in workspace member automatically, with no second login system. Works with any Lovable login method, and pairs with row-level security in the built-in backend (Cloud) for per-user data.
  </Card>

  <Card title="Roles and permissions" icon="user-shield" href="/features/collaboration">
    **All paid plans.** Owner, admin, editor, viewer, and external-collaborator.
  </Card>

  <Card title="Restrict workspace invitations" icon="ban" href="/features/privacy-and-security-settings#restrict-workspace-invitations">
    **Enterprise only.** Limit email invitations to admins and owners.
  </Card>

  <Card title="Workspace discovery" icon="magnifying-glass" href="/features/privacy-and-security-settings#workspace-discovery">
    **Business and Enterprise.** Let employees with a verified company email find and request to join your workspace. Owners and admins can turn this off in Privacy & security.
  </Card>
</CardGroup>

## Workspace governance and data protection

Set workspace-level policies once and apply them to every project. Most controls live in [Privacy & security](https://lovable.dev/settings/privacy-security) (**Workspace settings → Security → Privacy & security**).

<CardGroup cols={2}>
  <Card title="Privacy & security settings" icon="sliders" href="/features/privacy-and-security-settings">
    Reference for workspace privacy and security settings, including default project and website access, invitation controls, external collaborator modes, publishing gates, app login methods, auto-fix scope, preview-link control, MCP access, sensitive-data scanning, chat send protection, and extended-retention models.
  </Card>

  <Card title="App login methods" icon="key-skeleton" href="/features/privacy-and-security-settings#app-login-methods">
    **Business and Enterprise.** Workspace-wide lock-down of app sign-in methods (Email, Phone, Google, Apple, Microsoft, SAML SSO, Lovable workspace identity) across every project. Blocked methods can't be re-enabled per project.
  </Card>

  <Card title="Training data protection" icon="ban" href="/features/business/data-opt-out">
    **Business and Enterprise.** Workspace data is excluded from AI model training by default and governed by your organization's Data Processing Agreement. No opt-out is needed.
  </Card>

  <Card title="Sensitive data scanning and chat send protection" icon="user-magnifying-glass" href="/features/privacy-and-security-settings#sensitive-data-scanning">
    **Enterprise only.** Master switch for PII detection in project chat history, built-in databases, and storage (Cloud). Chat send protection modes: **Log only** (default), **Ask before sending**, or **Block original** (original message discarded, not logged).
  </Card>

  <Card title="Extended-retention models" icon="clock-rotate-left" href="/features/privacy-and-security-settings#extended-retention-models">
    **Enterprise only.** Enterprise workspaces use only zero-data-retention models by default. Admins can opt in to models whose provider retains prompts and outputs for 30 days, for building and for the AI features of published apps, after confirming the terms in a consent dialog.
  </Card>

  <Card title="EU inference" icon="earth-europe" href="/features/eu-inference">
    **Enterprise only.** Admins can keep the workspace's AI model requests on model endpoints in the European Union, for building and for the AI features in published apps. A request that no EU endpoint can serve fails instead of running in another region. Some features are not available while it is enabled.
  </Card>

  <Card title="Block public storage buckets" icon="bucket" href="/features/privacy-and-security-settings#block-public-storage-buckets">
    **All plans.** Workspace-wide safeguard that forces every new built-in storage bucket (Cloud) to private and prevents members from creating publicly accessible buckets.
  </Card>
</CardGroup>

## Publishing and sharing controls

Govern how projects are shared inside the workspace and how published apps reach the outside world. Publishing settings are managed in the [Privacy & security panel](/features/privacy-and-security-settings); project visibility and folder sharing are managed on each project or folder.

App login methods apply to every app in the workspace, see the [Workspace governance](#workspace-governance-and-data-protection) section above.

<CardGroup cols={2}>
  <Card title="Default website access" icon="lock" href="/features/privacy-and-security-settings#default-website-access">
    **Business and Enterprise.** Set the workspace default to **Workspace** so new publishes are only reachable by logged-in workspace members. Individual projects can still use the **Custom** audience to grant access to specific members, [groups](/features/groups), or [people outside the workspace invited by email](/features/publish#invite-people-outside-your-workspace).
  </Card>

  <Card title="Who can publish externally" icon="user-shield" href="/features/privacy-and-security-settings#who-can-publish-externally">
    **Enterprise only.** Restrict external publishing to admins and owners, or owners only.
  </Card>

  <Card title="External invite controls" icon="envelope" href="/features/privacy-and-security-settings#external-invites">
    **Business and Enterprise.** Turn off email invites for people outside the workspace, or restrict them to your company's [verified domains](/features/verified-domains) with [Who can receive external invites](/features/privacy-and-security-settings#who-can-receive-external-invites).
  </Card>

  <Card title="Disable public preview links" icon="eye-slash" href="/features/privacy-and-security-settings#preview-link-sharing">
    **Enterprise only.** Hide the **Share preview** button on every project workspace-wide.
  </Card>

  <Card title="Pre-publish security gates" icon="shield-exclamation" href="/features/privacy-and-security-settings#publishing">
    **All plans.** Block publishing with critical issues, and (Enterprise only) block publishing with unresolved PII findings.
  </Card>

  <Card title="Restricted projects" icon="lock-keyhole" href="/features/project-visibility">
    **Business and Enterprise.** Default new projects to **Restricted** so only the owner and invited collaborators can access them, at workspace and project level.
  </Card>

  <Card title="Personal folders and group folder sharing" icon="folder-tree" href="/introduction/project-folders">
    **Business and Enterprise.** Organize projects into private personal folders, or share folders with workspace members or [groups](/features/groups) so every project inside inherits the access.
  </Card>

  <Card title="Editor project transfers" icon="arrow-right-from-bracket" href="/features/privacy-and-security-settings#editor-project-transfers">
    **Enterprise only.** Control whether editors who own a project can transfer it to another workspace, including a personal workspace outside your organization. Disabled by default.
  </Card>

  <Card title="Require workspace editor role" icon="user-lock" href="/features/privacy-and-security-settings#require-workspace-editor-role">
    **Enterprise only.** Enforce a read-only baseline for viewers and external collaborators. When enabled, only members with the editor role or higher can edit projects, regardless of how project access was granted (direct, folder, or group). Disabled by default.
  </Card>
</CardGroup>

## Domains and branding

Manage app rollout under a consistent, workspace-branded URL pattern and connect custom domains in-app.

<CardGroup cols={2}>
  <Card title="Branded app URLs" icon="globe" href="/features/branded-workspace-urls">
    **Business and Enterprise.** Publish every app under a consistent `{app}.{workspace}.lovable.app` pattern derived from your [verified domain](/features/verified-domains).
  </Card>

  <Card title="Custom domains" icon="link" href="/features/custom-domain">
    **All paid plans.** Buy and connect domains in-app with Lovable handling DNS, SSL, and CDN front-ends.
  </Card>
</CardGroup>

## Audit and monitoring

Keep an auditable record of activity across the workspace, and a single place to track security posture and adoption across every project.

<CardGroup cols={2}>
  <Card title="Audit logs" icon="clipboard-clock" href="/features/audit-logs">
    **Enterprise only.** Searchable workspace activity logs for membership, roles, groups, SCIM, SSO, integrations, project lifecycle events, secrets, and prompts. Entries include actor, IP address, user agent, and structured JSON. Retained for 13 weeks (approximately 90 days). Longer retention and SIEM forwarding are available via your account team.
  </Card>

  <Card title="Workspace security center" icon="user-shield" href="/features/security-center">
    **Business and Enterprise.** Workspace-wide dashboard for code analysis, dependency vulnerabilities, secrets, and scan coverage across every project. CSV export. Trigger scans without opening individual projects.
  </Card>

  <Card title="Security insights" icon="chart-mixed" href="/features/security-insights">
    **Business and Enterprise.** Portfolio-level view of every project, combining security findings, ownership, lifecycle, publish status, and activity into a single review priority. Quick filters for abandoned projects, security findings, and projects with no owner. CSV export. PII findings and PII quick filters are Enterprise-only.
  </Card>

  <Card title="Insights" icon="chart-line" href="/features/insights">
    **Business and Enterprise.** Workspace adoption dashboard: visits, active apps, active builders, and connections added over the last 30 days, top apps ranked by visits, and builders ranked by edits. Adoption by department for workspaces that use SCIM. CSV export of the app and builder lists. Reports adoption, not security.
  </Card>
</CardGroup>

## Application security

Every publish runs a security scan automatically. Two built-in scans, **Quick scan** and **Deep scan**, plus optional connectors provide defense in depth from configuration to code review.

<CardGroup cols={2}>
  <Card title="Security overview" icon="shield-halved" href="/features/security">
    Quick scan runs on every publish and checks database access rules, dependencies, and MCP server exposure.
  </Card>

  <Card title="Deep scan" icon="magnifying-glass" href="/features/security#deep-scan">
    Optional review of your application code for access control, endpoint, input handling, secret, payment, sign-in, and data exposure issues.
  </Card>

  <Card title="Project security view" icon="bug" href="/features/security-view">
    Per-project home for findings from every scanner, including Aikido and Wiz. Inline chat to fix any finding.
  </Card>

  <Card title="Schedule Deep security scans" icon="calendar-clock" href="/features/security-center#schedule-security-scans-enterprise-only">
    **Enterprise only.** Weekly or monthly Deep scans across published projects or all projects. 1 credit per project per run.
  </Card>

  <Card title="Auto-fix security issues" icon="wrench" href="/features/privacy-and-security-settings#auto-fix-security-issues">
    Workspace default for auto-remediating eligible Quick-scan findings. Scopes: Selected project, Externally published, All published, or All projects.
  </Card>

  <Card title="Aikido AI pentest" icon="user-ninja" href="/integrations/aikido">
    Agentic dynamic penetration testing with real attack payloads. Generates SOC 2 and ISO 27001-ready reports.
  </Card>

  <Card title="Wiz security scanning" icon="shield-check" href="/integrations/wiz">
    Software composition analysis (SCA) and static application security testing (SAST) across every project. Connect your Wiz deployment with one OAuth flow.
  </Card>

  <Card title="Security best practices" icon="book" href="/tips-tricks/security-best-practices">
    Practical guidance for writing secure code in Lovable apps.
  </Card>
</CardGroup>

Leaked-password protection using Have I Been Pwned (HIBP) for end-user email sign-in and conversational security review in chat are both available alongside the scanners, see [Security overview](/features/security).

## Code hosting, residency, and deployment control

Keep code data inside a specific GitHub region, on your own self-hosted infrastructure, or on hosting you operate yourself.

<CardGroup cols={2}>
  <Card title="GitHub Enterprise Cloud (data residency)" icon="github" href="/integrations/github">
    **Enterprise only.** Connect Lovable to GitHub Enterprise Cloud on a `*.ghe.com` hostname so repository data and webhook traffic stay in your assigned region.
  </Card>

  <Card title="GitHub Enterprise Server (self-hosted)" icon="server" href="/integrations/github">
    **Enterprise only.** Connect Lovable to your self-hosted GitHub Enterprise Server. You create the GitHub app inside your own organization; signing keys remain under your control.
  </Card>

  <Card title="GitLab (cloud and self-managed)" icon="gitlab" href="/integrations/gitlab">
    Sync projects to GitLab.com or your self-managed GitLab instance.
  </Card>

  <Card title="Bitbucket Cloud" icon="bitbucket" href="/integrations/bitbucket">
    Sync projects to a Bitbucket Cloud workspace on your Atlassian account.
  </Card>

  <Card title="Hosting and ownership decisions" icon="map" href="/tips-tricks/deployment-hosting-ownership">
    The recommended path for managing where code and data live. Start on Lovable, sync your code with Git, move components out only when you hit a real constraint.
  </Card>

  <Card title="Host outside Lovable" icon="cloud-arrow-up" href="/tips-tricks/external-deployment-hosting">
    Move backend and database to infrastructure you operate (including self-hosted Supabase) when compliance, residency, or organizational policy requires it.
  </Card>
</CardGroup>

## Enterprise integrations and developer controls

Connect Lovable to the tools your team already uses, plug into existing data warehouses, and drive Lovable programmatically from your own systems.

<CardGroup cols={2}>
  <Card title="Connector catalog" icon="plug" href="/integrations/introduction">
    50+ connectors (Linear, Slack, Twilio, Notion, Atlassian, HubSpot, Microsoft, Google Workspace, AWS S3, Stripe, Supabase, and more). **Business and Enterprise** workspaces control who can create connections and clients per connector, which is also how connectors are made available or disabled.
  </Card>

  <Card title="Data and analytics" icon="warehouse" href="/integrations/introduction">
    First-class connectors for [Databricks](/integrations/databricks) (service-principal OAuth), [Snowflake](/integrations/snowflake) (custom OAuth integration), [BigQuery](/integrations/bigquery) (Workload Identity Federation, no stored keys), and [Gemini Enterprise](/integrations/gemini-enterprise) for search and grounded answers across connected data sources.
  </Card>

  <Card title="Chat connectors (MCP)" icon="comments" href="/integrations/chat-connectors">
    Featured plus custom MCP servers. Enterprise workspaces can route custom MCP traffic through [Lovable static IPs](/integrations/custom-mcp#lovable-static-ips) to reach servers behind IP-allowlisting firewalls. Workspace admins control **Remote MCP connectors**, **Local desktop MCP servers**, and **Third-party MCP clients** (disabled by default on Enterprise) under Privacy & security.
  </Card>

  <Card title="Lovable MCP server" icon="terminal" href="/integrations/lovable-mcp-server">
    Drive Lovable from external MCP clients, such as Claude Desktop, Cursor, and Claude Code. Enterprise workspaces must explicitly enable third-party MCP client access.
  </Card>

  <Card title="Build with URL" icon="code" href="/integrations/build-with-url">
    Create prompt links from internal portals or workflow tooling. They open in Lovable ready to send.
  </Card>

  <Card title="Desktop and mobile" icon="desktop">
    [Desktop app for macOS and Windows](/integrations/desktop-app), plus [iOS and Android apps](/integrations/lovable-mobile-app). Available on all plans.
  </Card>
</CardGroup>

## Developer standards and reuse

Define design, components, engineering conventions, and project organization once so every new project starts from an approved baseline.

<CardGroup cols={2}>
  <Card title="Workspace knowledge" icon="book" href="/features/knowledge">
    Coding standards, architecture rules, and preferred libraries that stay consistent across every project. Project-level overrides supported.
  </Card>

  <Card title="Design templates" icon="palette" href="/features/business/design-templates">
    **Business and Enterprise.** Mark any project as a reusable template. Set a workspace default template.
  </Card>

  <Card title="Design systems" icon="layer-group" href="/features/design-systems">
    **All paid plans.** Define your React component library, styling rules, and setup once. Connected projects pick up updates on every new generation. Wrapping an existing npm package as a design system is **Enterprise only**.
  </Card>

  <Card title="Cross-project referencing" icon="link-simple" href="/features/cross-project-referencing">
    `@`-mention other projects in the workspace and reuse implementations, files, and chat context.
  </Card>

  <Card title="Build secrets" icon="key" href="/features/build-secrets">
    **Enterprise only.** Encrypted workspace-level environment variables for builds. Configured in [Build secrets](https://lovable.dev/settings/secrets) (**Workspace settings → Build & deploy → Build secrets**).
  </Card>
</CardGroup>

## Cost and spend controls

Set credit limits and alerts, track workspace usage, and customize commitments through your Enterprise contract.

<CardGroup cols={2}>
  <Card title="Usage limits & alerts" icon="bell" href="/features/usage-limits-and-alerts">
    **All paid plans.** Set credit limits for the workspace, projects, members, groups, and access tokens, plus low-balance alerts on the workspace balance. Each limit can notify you, block usage at its threshold, or both, and members can request limit increases for you to approve.
  </Card>

  <Card title="Per-member credit limits" icon="gauge" href="/features/people#set-a-per-member-credit-limit">
    **All paid plans.** Workspace default plus per-member overrides. Resets the 1st of every month at 00:00 UTC. Enterprise workspaces can also [import limits for many members at once from a CSV](/features/people#import-credit-limits-from-a-csv).
  </Card>

  <Card title="Credits and usage" icon="wallet" href="/introduction/credits-and-usage">
    Track Build usage, Cloud usage, AI gateway usage, and connector usage from **Workspace settings → Plans & credit usage**. View credit balances, usage details, and credit history in one place.
  </Card>

  <Card title="Custom commitments" icon="handshake" href="https://lovable.dev/enterprise">
    Enterprise contracts can include custom credit commitments, custom seat caps, and annual billing terms.
  </Card>

  <Card title="Workspace member CSV export" icon="file-csv" href="/features/people#export-the-member-list">
    Export the full member list with usage, credit limits, and the effective limit that applies to each member for finance and provisioning audits.
  </Card>
</CardGroup>

## Compliance

Lovable's compliance program is published at the [Trust portal](https://trust.lovable.dev) and on the [Security page](https://lovable.dev/security).

* **SOC 2 Type II**
* **ISO 27001:2022**
* **AIUC-1**
* **GDPR**, with a [Data Processing Agreement](https://lovable.dev/data-processing-agreement)
* [Privacy Policy](https://lovable.dev/privacy)
* Current sub-processor list at [trust.lovable.dev](https://trust.lovable.dev)

## Support

Enterprise workspaces include a commercial relationship beyond the product itself:

* **Dedicated account team**, single point of contact for onboarding, growth, and escalations
* **Priority support** with response SLAs
* **Custom onboarding** tailored to your team's roles and workflows
* **Custom member caps** to match procurement or licensing requirements
* **SIEM integration for audit logs**, work with your account team to forward audit events
* **Workspace deletion**, Enterprise workspaces are retired through your account team. See [Delete a workspace](/introduction/delete-workspace).

## Get started

<Card title="Talk to our sales team" icon="arrow-right" horizontal href="https://lovable.dev/enterprise">
  Tell us about your team's identity provider, compliance requirements, and use case. We'll set up an Enterprise workspace and walk through migration from your existing plan if needed.
</Card>

## FAQ

<AccordionGroup>
  <Accordion title="What's the difference between Business and Enterprise?">
    Business is the self-serve top tier with workspace SSO, groups, Security center, Insights, App login methods, design templates, branded app URLs, restricted projects, training-data exclusion by default, and workspace-level connector controls.

    Enterprise is a contract plan that adds SCIM provisioning, audit logs, scheduled Deep security scans, sensitive data scanning and chat send protection, block publishing with PII, design systems based on an existing npm package, build secrets, EU inference, GitHub Enterprise Cloud (data residency) and Server connections, Lovable static IPs for custom MCP servers, restrict-invitations and restrict-external-publishing controls, project transfer controls, disable-public-preview-link control, third-party MCP client gating, bulk domain provisioning, custom commitment credits, custom member caps, and a dedicated account team.
  </Accordion>

  <Accordion title="How do we move from Business to Enterprise?">
    Contact our sales team. We'll set up the Enterprise workspace, migrate your members and projects, and configure SCIM, audit logs, and any Enterprise-only controls you need.
  </Accordion>

  <Accordion title="Does Lovable support our identity provider?">
    Lovable supports any **OIDC** or **SAML 2.0**-compliant identity provider. Step-by-step guides are published for **Okta**, **Auth0**, and **Microsoft Entra ID**, plus generic instructions for other providers. SCIM is supported for Okta, Microsoft Entra ID (via SAML app), and any SCIM 2.0-compliant identity provider.
  </Accordion>

  <Accordion title="How often do security scans run?">
    **Quick scans** run automatically when the publish dialog opens. The dependency audit also runs whenever your project's dependencies change.

    **Deep scans** run when you start them from the Security view or Security center, on the schedule below, or when you publish an app whose MCP integration allows access without sign-in.

    On Enterprise, admins can additionally **schedule Deep scans** weekly (Monday 08:00 workspace timezone) or monthly (1st 08:00) across published projects or all projects.

    Scheduled scans are billed at **1 credit per project per run**; on-demand scans are free.
  </Accordion>

  <Accordion title="Can our security team detect or block sensitive data in chats?">
    Yes, on Enterprise. Enable **Sensitive data scanning** in Privacy & security to turn on the workspace-wide master switch, then choose a **Chat send protection** mode:

    * **Log only** (default): scans run and findings are recorded in the project's Sensitive data tab; messages send without interruption.
    * **Ask before sending**: detected PII pauses the message, the user edits, sends a redacted version, or sends the original.
    * **Block original**: the original cannot be sent. The user must edit or redact. The original message is discarded and **not logged**.

    Sensitive data scanning also unlocks on-demand scans of project chat history, built-in databases, and storage, plus the **Block publishing with PII** gate.
  </Accordion>

  <Accordion title="Can workspace admins control which login methods apps accept?">
    Yes. **App login methods** in [Privacy & security](https://lovable.dev/settings/privacy-security) (**Workspace settings → Security → Privacy & security → App login methods**) lets Business and Enterprise admins block [Email](/features/email-auth), [Phone](/features/phone-auth), [Google](/features/google-auth), [Apple](/features/apple-auth), [SAML SSO](/features/saml-sso), or [Lovable workspace identity](/features/lovable-workspace-identity-reuse) across every app in the workspace. Blocked methods can't be re-enabled per project. This only affects login methods for apps your workspace builds, not how workspace members log in to Lovable.
  </Accordion>

  <Accordion title="Can editors move projects outside our organization?">
    Not by default on Enterprise. **Project transfer controls** let admins decide whether editors who own a project can transfer it to another workspace, including a personal workspace outside your organization. For regulated environments, leave this disabled so only admins and owners can initiate project transfers and projects stay inside your governance boundary.
  </Accordion>

  <Accordion title="How long are audit logs retained?">
    Audit logs are retained for **13 weeks, approximately 90 days** in-product. For longer retention or SIEM forwarding, contact your account team.
  </Accordion>

  <Accordion title="Where is our code stored?">
    By default, project code lives in Lovable's managed infrastructure. On Enterprise you can keep code in **GitHub Enterprise Cloud with data residency** (so repository data and webhook traffic stay in a specific region) or in **GitHub Enterprise Server** running on your own infrastructure with credentials and signing keys under your control.
  </Accordion>

  <Accordion title="Can AI processing stay in the European Union?">
    Yes, on Enterprise. When an admin enables [EU inference](/features/eu-inference) in [Privacy & security](https://lovable.dev/settings/privacy-security) (**Workspace settings → Security → Privacy & security**), Lovable sends the workspace's AI model requests to model endpoints in the European Union, for building and for the AI features in published apps. A request that no EU endpoint can serve fails instead of running in another region. Fewer models are available while it is enabled, some features are not available, and the workspace uses more credits.
  </Accordion>

  <Accordion title="Is Lovable HIPAA-compliant?">
    No. Lovable does not currently sign Business Associate Agreements and is not HIPAA-compliant. Do not upload protected health information or other restricted categories of data.
  </Accordion>

  <Accordion title="How does billing work for Enterprise?">
    Enterprise plans use custom contractual pricing with annual commitments and optional custom credit commitments. Talk to sales for a quote.
  </Accordion>
</AccordionGroup>


## Related topics

- [Sync your Lovable project with GitHub](/integrations/github.md)
- [Welcome to Lovable](/introduction/welcome.md)
- [Support policy](/introduction/support-policy.md)
- [Managed registry](/features/managed-registry.md)
- [Connect your app to Gemini Enterprise](/integrations/gemini-enterprise.md)
