Security & Compliance

Enterprise-Grade Security

Your data is protected by industry-leading security measures, continuous auditing, and strict access controls.

SOC 2 Type II
FedRAMP Authorized
AES-256 Encryption

Data Encryption

  • AES-256 encryption at rest

    All stored data is encrypted using AES-256-GCM, the same standard used by financial institutions and government agencies.

  • TLS 1.3 in transit

    Every connection uses TLS 1.3 with perfect forward secrecy — no data ever travels unencrypted.

  • End-to-end encrypted storage

    Documents, proposals, and knowledge base entries are encrypted before they reach our storage layer.

Compliance

  • SOC 2 Type II certified

    Independently audited controls for security, availability, and confidentiality.

  • FedRAMP authorized

    Meets the rigorous security requirements for U.S. federal government cloud services.

  • GDPR compliant

    Full compliance with EU data protection regulations, including data export and deletion rights.

  • CCPA compliant

    California Consumer Privacy Act protections for all users, regardless of location.

Infrastructure

  • AWS hosting (US-based)

    Deployed across multiple AWS availability zones in the United States for redundancy and low latency.

  • 99.9% uptime SLA

    Contractual uptime guarantee backed by automated failover and health monitoring.

  • Automated backups

    Point-in-time recovery with encrypted backups retained for 30 days.

Access Controls

  • Role-based permissions

    Granular RBAC lets admins control who can view, edit, and manage projects and settings.

  • SSO / SAML support

    Enterprise plans include SAML 2.0 single sign-on with Okta, Azure AD, Google Workspace, and more.

  • 2FA / MFA available

    Multi-factor authentication adds a second layer of protection to every account.

AI & Data Privacy

Your data is never used to train AI models.
  • No AI training on your data

    Your documents, proposals, and knowledge base content are never used to train, fine-tune, or improve any AI model.

  • Ephemeral processing

    Data sent to AI providers is processed in real-time and not stored or retained after the response is generated.

  • Third-party provider policies

    We use Google Gemini and Anthropic Claude, both of which contractually exclude API inputs from model training under their standard API terms.

  • Data isolation

    Each organization's data is logically isolated via row-level security. No cross-tenant data access is possible.

  • You own your data

    Export or delete your data at any time. We never claim ownership of your content.

Compliance Documentation

Access our audit reports, penetration testing results, and privacy policies.

SOC 2 Type II Report

Request our latest SOC 2 Type II audit report under NDA.

Penetration Testing

Annual third-party penetration tests by independent security firms. Summary available on request.

Privacy Policy

Read our full data privacy and protection policy.

Questions about security?

Our security team is ready to answer questions, provide documentation, or schedule a review.

View FAQ