Production traffic is served over HTTPS/TLS, with HSTS instructing supported browsers to continue using HTTPS.
GrantProof Trust Center
Current controls, current limitations, and no invented security claims.
This page describes controls operating in GrantProof's current early-access code. It is not a third-party certification, legal conclusion, audit opinion, or promise about controls that are still being developed.
Last reviewed July 15, 2026 · Stage: Early access
Operating today
Verified safeguards
These statements map to controls in the production-target code and shared security configuration.
Database and file-storage encryption at rest are provided by the configured infrastructure providers.
Authenticated requests are authorized on the server against the active organization membership.
GrantProof-hosted uploads are private and are served through an authenticated, organization-scoped file route using non-guessable storage names.
Session cookies are HttpOnly, Secure in production, and SameSite-scoped; revoking a membership removes its active sessions.
Passwords are protected with one-way hashing and are not stored as readable plaintext.
Password reset links are single-use, expire one hour after they are requested, and are stored only as hashes; requesting a new link retires any earlier one, and redeeming a link ends every active session for that account.
Evidence uploads use a deny-by-default file allowlist, a 3 MB application limit, and byte-level format checks; executable, script, active web-file, and legacy binary Office formats are rejected.
Evidence can be archived reversibly, restored as Needs review, or permanently deleted with an explicit confirmation step.
Permanent evidence deletion removes the application record immediately and durably queues an unshared GrantProof-hosted file for deletion and retry; shared files remain until their final live reference is deleted, and external cloud links remain in the customer's storage.
Organization owners can permanently purge the organization, its application records, memberships, and GrantProof-hosted files after exact-name confirmation, password step-up, and fail-closed billing verification.
Security-relevant actions are recorded in the organization audit history where implemented.
The optional AI assistant treats customer-entered and document-derived content as untrusted evidence rather than instructions.
Application logging uses redaction rules for credentials, tokens, email addresses, notes, document text, and other sensitive fields.
GrantProof does not sell customer data or use customer records to train AI models.
Product usage analytics are first-party and stored in GrantProof's own database. No third-party analytics or advertising trackers are loaded, and event records hold identifiers, event names, and low-cardinality metadata — never document contents, evidence titles, notes, or free text.
Support requests are scoped to your organization: organization owners and administrators see every request their organization raised, other members see only their own, and no organization can read another's requests, survey answers, or usage records.
Support conversations keep staff-internal notes in separate storage from the replies you can read, so an internal note cannot be shown to a customer.
Files attached to a support request are stored privately and served through the same authenticated route as evidence. GrantProof support staff can open the files attached to a support request and nothing else in your workspace, and every such access is recorded.
Every GrantProof staff view of support, analytics, or customer-learning data is recorded in an access log that is retained separately from your organization's own audit history.
Deleting your organization deletes its support requests, messages, attachments, internal notes, survey responses, and product-usage records, and queues its attachment files for deletion from storage.
Product-usage records are deleted after a configured retention window (24 months by default), and the staff access log after 12 months.
Surveys are short, are offered to one person per organization rather than everyone, can be deferred or declined, and are never shown as an interruption inside a workflow.
Customer data controls
Archive is not deletion
GrantProof keeps reversible record management separate from irreversible deletion so customers can make an informed choice.
Archive and restore
Archive is reversible. Archived evidence is hidden from the normal Evidence Binder view, remains stored, and can be restored as Needs review.
Permanent document deletion
A separate confirmed action deletes the evidence record and its GrantProof-hosted stored file. External cloud links remain in the customer's own storage.
Organization deletion
Organization owners can permanently purge the organization's grants, evidence, findings, reports, memberships, and GrantProof-hosted files after typing the organization name.
Important boundaries
What GrantProof does not claim
Detailed documentation
Review the implementation details
Security overview
Architecture, access, storage, deletion, and early-access limitations.
AI data handling
What the assistant receives and how untrusted document content is handled.
Subprocessors
Current service providers, purposes, and categories of data shared.
Downloadable overview
A concise vendor-review reference for prospective customers.
Ask before uploading
Security and data-handling questions are welcome
GrantProof will answer with the controls and operational practices that are currently verified rather than inventing a certification, retention period, backup promise, or recovery objective.
Security contact
Contact GrantProof
Questions about access, deletion, storage, AI, vendors, or early-access limitations.
Email security contact