Trust & Security

Your Security is Our Priority

ProposalVault is built with security-first principles. We understand you're trusting us with sensitive compliance documentation, and we take that responsibility seriously.

Encryption
Data protection at every layer
  • HTTPS connections with HSTS enabled
  • Encryption at rest provided by our infrastructure providers
  • Security headers including CSP, frame denial, and MIME protection
Infrastructure
Enterprise-grade hosting
  • Next.js application hosted on Vercel
  • Neon Postgres with pgvector for application data and search embeddings
  • Better Auth sessions and Upstash-backed distributed rate limiting
AI Sub-processors
How AI requests are handled
  • OpenAI processes text submitted for search embeddings
  • Groq processes questions and relevant workspace excerpts for drafting
  • Provider processing, retention, and training controls follow configured account settings and provider terms
Access Controls
Who can access your data
  • Viewer, Editor, and Admin workspace roles
  • Application-level workspace scoping and server-side authorization checks
  • Better Auth credential records use one-way scrypt password hashing
AI & Data Usage
How we use AI responsibly
  • Requests are sent to provider APIs over encrypted connections
  • Original uploads are processed to extract text and are not stored by the active upload flow
  • Extracted text and embeddings are stored in the authorized workspace
Data Retention
Your data, your control
  • Request deletion through support
  • Approved requests remove data from active systems
  • Export your data before deletion

Important Disclaimers

Security Limitations

While we implement industry-standard encryption and security measures, no system can be guaranteed to be completely secure. We continuously work to improve our security posture, but users should be aware that all technology systems carry inherent risks.

Engineer Access

Authorized engineers may access user data only when required for debugging, security investigations, or customer support purposes. Such access is restricted to necessary personnel under internal access controls; comprehensive engineer-access logging is still being developed.

User Responsibility

Users are responsible for reviewing and verifying all AI-generated content and uploaded documents before use. ProposalVault does not verify the accuracy of user-submitted or AI-generated content. Actual results may vary based on the quality and relevance of uploaded source documents.

AI Provider Data Handling

OpenAI processes text to create embeddings, while Groq processes questions and relevant document excerpts to generate answers or extract questions. Provider retention and training controls depend on our account configuration and their applicable terms, and temporary abuse-monitoring retention may apply.

Compliance status
A clear statement of our current position

ProposalVault does not currently hold a SOC 2 certification or ISO 27001 certification. We use security controls appropriate to a lean SaaS product and rely on third-party infrastructure providers with their own security programs.

What this means: We do not represent ProposalVault as certified or compliant with a security framework that we have not independently attested to. Questions about our current practices can be sent to support.

For security questionnaires or to request our security documentation, please contact support@proposalvault.cloud

Subprocessors

We use the following third-party services to provide ProposalVault:

ProviderPurposeLocation
VercelApplication hostingUnited States
NeonDatabase hostingUnited States
GoogleOptional social authenticationGlobal
BrevoTransactional email deliveryUnited States
OpenAIDocument embeddingsUnited States
GroqAI inferenceUnited States
StripePayment processingUnited States
UpstashDistributed rate limitingConfigured database region

Vulnerability & access

We investigate reported vulnerabilities and security incidents and limit access to customer data to authorized personnel with a legitimate business need.

  • Security reports can be submitted to support@proposalvault.cloud
  • We assess impact and communicate with affected customers when required by applicable law or our contractual commitments
  • Application access is governed by Viewer, Editor, and Admin workspace roles

Security FAQ

Do you have a SOC 2 report?

No. ProposalVault does not currently hold a SOC 2 certification or ISO 27001 certification. Contact support with questions about our current security practices.

Is my data used to train AI models?

We use business API services and do not intentionally opt customer content into model training. OpenAI and Groq processing remains subject to our account settings and their applicable data-use and temporary retention terms.

Can I get a copy of my data?

Paid plans can export project content in supported formats. For deletion or other data requests, contact support; requests are reviewed and handled subject to applicable law and provider backup-retention requirements.

How do I report a security vulnerability?

Please email support@proposalvault.cloud with details of the vulnerability. We review responsible-disclosure reports and will respond as appropriate to their severity and the information provided.

Contact & Support

General Support

Need help with your account, have a question, or want to provide feedback?

support@proposalvault.cloud

Replies within 1 business day

Security & Compliance

For security questionnaires, vulnerability reports, or compliance documentation:

support@proposalvault.cloud

Have security questions?

Our team is happy to answer security questionnaires and provide documentation.