Security & Trust
GrantProof handles sensitive grant records. This page summarizes the controls, data-handling practices, and current limitations customers need to evaluate the service. Additional technical information is available for legitimate vendor reviews.
Current safeguards
- GrantProof uses encrypted connections for production traffic and provider-supported encryption for stored customer data.
- Authenticated access is scoped to the customer organization and the role assigned to each member.
- Customer uploads are private rather than publicly indexed or intentionally exposed as public assets.
- Passwords are protected with one-way credential protection and are not stored as readable text.
- GrantProof does not sell customer data or use customer records to train AI models.
- Product analytics are first-party and designed to measure meaningful product use without advertising trackers.
Data handling and deletion
GrantProof is designed to work with grant records, budgets, evidence, deadlines, and team information. Customers should upload only what is needed for grant-readiness work and redact unnecessary personal identifiers before upload.
Customers can remove individual evidence records and can request or perform organization-level deletion through the product. GrantProof removes access to deleted application data and processes deletion of GrantProof-hosted files subject to provider-controlled infrastructure retention and backup behavior.
AI use
AI-assisted functionality is optional. GrantProof does not use customer data to train models. The public AI policy explains the categories of information that may be used for an explicitly requested assistant action and the categories that are excluded.
Subprocessors
GrantProof publishes the third parties that may process customer data and the purpose for which each is used.
What GrantProof does not claim yet
GrantProof is an early-stage product. We do not present planned controls or certifications as completed controls.
- GrantProof has not completed SOC 2 or an independent third-party security audit.
- GrantProof does not currently offer a HIPAA Business Associate Agreement; do not upload Protected Health Information.
- Enterprise authentication features such as multi-factor authentication and single sign-on are not part of the current baseline.
- GrantProof does not publish contractual recovery objectives that have not been formally established and verified.
Need a deeper vendor review?
Legitimate prospects and customers can request additional architecture, data-flow, and control information directly. Email erica@grantreadysystems.com.
Report a security concern
To report a vulnerability, email erica@grantreadysystems.com. Please do not include live customer data in the report.