Security at ProposalPilot

Last updated: October 2, 2026

Your proposals contain sensitive business information. This page describes the controls we use today and the limits of what we claim.

Data isolation

Every workspace is isolated by database row-level security, enforced in the database itself rather than only in application code. Uploaded files live in a private storage bucket and are downloaded through short-lived signed links.

Encryption

  • Data is encrypted in transit with TLS and strict transport security.
  • AI provider keys and integration credentials are encrypted with AES-256-GCM before storage and are never returned to the browser.
  • Direct messages are end-to-end encrypted in the browser (ECDH P-256, HKDF-SHA-256, AES-256-GCM); we store only ciphertext.

Application security

  • Strict content-security policy with per-request nonces, CSRF protection and security headers.
  • Per-user rate limiting on sensitive endpoints, and magic-byte validation of uploaded files.
  • Server-side request protection (SSRF guards) for customer-supplied AI endpoints and pinned hosts for integrations.
  • Dependencies are audited and monitored automatically.

Access control and auditing

  • Admin, Editor and Reviewer roles; invitations are single-use, expire, and are tied to an email.
  • Removing a member immediately revokes access.
  • An append-only audit log records important workspace changes.

Standards alignment and honesty

Our design follows OWASP guidance and NIST recommendations and uses FIPS-approved algorithms. We do not currently hold SOC 2, ISO 27001 or FIPS 140 validation, and we say so in security questionnaires. Direct messages have no forward secrecy.

Reporting a vulnerability

If you believe you've found a security issue, please report it through the contact form with the topic “Security”. Give us reasonable time to investigate and fix it before disclosing publicly, and avoid accessing data that isn't yours.

See also our Privacy Policy, Subprocessors and Contact page.