ProposalVault is built with security-first principles. We understand you're trusting us with sensitive compliance documentation, and we take that responsibility seriously.
While we implement industry-standard encryption and security measures, no system can be guaranteed to be completely secure. We continuously work to improve our security posture, but users should be aware that all technology systems carry inherent risks.
Authorized engineers may access user data only when required for debugging, security investigations, or customer support purposes. Such access is restricted to necessary personnel under internal access controls; comprehensive engineer-access logging is still being developed.
Users are responsible for reviewing and verifying all AI-generated content and uploaded documents before use. ProposalVault does not verify the accuracy of user-submitted or AI-generated content. Actual results may vary based on the quality and relevance of uploaded source documents.
OpenAI processes text to create embeddings, while Groq processes questions and relevant document excerpts to generate answers or extract questions. Provider retention and training controls depend on our account configuration and their applicable terms, and temporary abuse-monitoring retention may apply.
ProposalVault does not currently hold a SOC 2 certification or ISO 27001 certification. We use security controls appropriate to a lean SaaS product and rely on third-party infrastructure providers with their own security programs.
What this means: We do not represent ProposalVault as certified or compliant with a security framework that we have not independently attested to. Questions about our current practices can be sent to support.
For security questionnaires or to request our security documentation, please contact support@proposalvault.cloud
We use the following third-party services to provide ProposalVault:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| Neon | Database hosting | United States |
| Optional social authentication | Global | |
| Brevo | Transactional email delivery | United States |
| OpenAI | Document embeddings | United States |
| Groq | AI inference | United States |
| Stripe | Payment processing | United States |
| Upstash | Distributed rate limiting | Configured database region |
We investigate reported vulnerabilities and security incidents and limit access to customer data to authorized personnel with a legitimate business need.
No. ProposalVault does not currently hold a SOC 2 certification or ISO 27001 certification. Contact support with questions about our current security practices.
We use business API services and do not intentionally opt customer content into model training. OpenAI and Groq processing remains subject to our account settings and their applicable data-use and temporary retention terms.
Paid plans can export project content in supported formats. For deletion or other data requests, contact support; requests are reviewed and handled subject to applicable law and provider backup-retention requirements.
Please email support@proposalvault.cloud with details of the vulnerability. We review responsible-disclosure reports and will respond as appropriate to their severity and the information provided.
Need help with your account, have a question, or want to provide feedback?
support@proposalvault.cloudReplies within 1 business day
For security questionnaires, vulnerability reports, or compliance documentation:
support@proposalvault.cloud