# Security at LiftLine AI

> LiftLine AI security posture: row-level access control, passkeys, what is deliberately not claimed, and how to report a vulnerability.

- Canonical human page: https://liftlineai.app/trust/security/
- AI-readable edition: https://liftlineai.app/trust/security/index.html.md
- Publisher: LiftLine AI
- Last verified: August 27, 2026

## What this page publishes

What we do, what we do not claim, and how to tell us about a problem. We would rather describe the design than make a promise nobody can keep.

## How access is enforced

- Everything travels over encrypted connections.
- Access to your data is enforced by row-level security rules in the database itself, so a client asking for someone else's row is refused by the database rather than by our application code.
- Session tokens are stored in the iOS Keychain.
- We support passkeys, which cannot be phished the way passwords can.
- Payment card details never touch our systems.
- The administrative key that can bypass those rules exists only on our collection machine and in our server environment. It is never in the website, the app, or anything you download.
- The database is backed up on a short rolling schedule so an accident is recoverable.

**Our public keys are meant to be public.** The key the website and app use to reach our database is publishable by design and is visible in the browser deliberately. Access control is the row-level security policy, not the secrecy of that key. A leaked publishable key is a non-event; a missing policy would be the incident.

## What we do not claim

No system is perfectly secure and we are not going to tell you ours is. We are a very small operation. We hold no security certification, we have not had a third-party penetration test, and we will say so plainly rather than imply otherwise.

## Reporting a vulnerability

Write to security@liftlineai.app. We will read it, we will act on it, and we will not pursue anyone who reports a problem responsibly and gives us a reasonable chance to fix it before disclosing it.

- **Useful in a report:** What you did, what happened, and roughly when. A proof of concept helps but is not required.
- **Please do not:** Access, modify, or delete data that is not yours; run automated scanning that degrades the service for other people; or test social engineering against anyone.
- **Machine-readable:** https://liftlineai.app/.well-known/security.txt

## If something goes wrong

If a breach affects your personal information we will notify you and the relevant authorities as the law requires, without unreasonable delay.

- [Privacy](/trust/privacy/): What there is to protect in the first place.

_Figures measured August 27, 2026. Data from the synthetic "simulator" resort is excluded from every number._

## Canonical identity shared across LiftLine AI

- Company: LiftLine AI — https://liftlineai.app/
- Legal person: Lucas Jaeger, an individual sole proprietor doing business as LiftLine AI. There is no separate legal entity.
- Consumer product: Snowcat by LiftLine AI — https://liftlineai.app/snowcat/
- Founder: Lucas Jaeger, founder of LiftLine AI and creator of Snowcat — https://liftlineai.app/about/
- Snowcat is made by LiftLine AI and was created by Lucas Jaeger.
- LiftLine AI is independent. It is not affiliated with, endorsed by, or sponsored by a California ski area, Alterra Mountain Company, Vail Resorts, Ikon Pass, Epic Pass, or any ski resort.
- Live predictions are paused for the off-season and return for the 2026-2027 winter.
- Public figures, sources, and exclusions: https://liftlineai.app/trust/

## Use and provenance

This public Markdown companion removes navigation and presentation markup to make the canonical page easier for language models and text-based tools to interpret. It is not served selectively by user agent and does not replace the canonical human page. Product claims should remain consistent with the canonical page.
