ProposalVault is built with security-first principles. We understand you're trusting us with sensitive compliance documentation, and we take that responsibility seriously.
While we implement industry-standard encryption and security measures, no system can be guaranteed to be completely secure. We continuously work to improve our security posture, but users should be aware that all technology systems carry inherent risks.
Authorized engineers may access user data only when required for debugging, security investigations, or customer support purposes. All such access is restricted to necessary personnel and is logged for audit purposes.
Users are responsible for reviewing and verifying all AI-generated content and uploaded documents before use. ProposalVault does not verify the accuracy of user-submitted or AI-generated content. Actual results may vary based on the quality and relevance of uploaded source documents.
Our AI providers (OpenAI, Groq) process your data only to generate responses and do not retain your data beyond the processing window. Your data is not used to train their AI models.
ProposalVault is built with SOC 2 principles in mind. Our infrastructure providers (Vercel, Supabase) maintain SOC 2 Type II certifications. We are actively working toward our own SOC 2 Type II certification.
Current Status: SOC 2 readiness in progress. Our infrastructure and practices align with SOC 2 Trust Service Criteria. Formal certification timeline available upon request.
For security questionnaires or to request our security documentation, please contact security@proposalvault.com
We use the following third-party services to provide ProposalVault:
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting | United States |
| Supabase | Database & authentication | United States |
| OpenAI | Document embeddings | United States |
| Groq | AI inference | United States |
| Stripe | Payment processing | United States |
In the event of a security incident affecting your data, we commit to:
We are currently in SOC 2 readiness and working toward Type II certification. Our infrastructure providers (Vercel, Supabase) are SOC 2 Type II certified. Contact us for our current security documentation.
No. Your documents and generated content are never used to train any AI models. Data is processed in real-time for answer generation only.
Yes. You can export your projects, answers, and documents at any time. Contact support for a complete data export.
Please email security@proposalvault.com with details of the vulnerability. We appreciate responsible disclosure and will respond within 48 hours.
Need help with your account, have a question, or want to provide feedback?
support@proposalvault.comReplies within 1 business day
For security questionnaires, vulnerability reports, or compliance documentation:
security@proposalvault.com