GrantProof Trust Center

Current controls, current limitations, and no invented security claims.

This page describes controls operating in GrantProof's current paid-pilot code. It is not a third-party certification, legal conclusion, audit opinion, or promise about controls that are still being developed.

Last reviewed July 15, 2026 · Stage: Paid pilot

Operating today

Verified safeguards

These statements map to controls in the production-target code and shared security configuration.

Production traffic is served over HTTPS/TLS, with HSTS instructing supported browsers to continue using HTTPS.

Database and file-storage encryption at rest are provided by the configured infrastructure providers.

Authenticated requests are authorized on the server against the active organization membership.

GrantProof-hosted uploads are private and are served through an authenticated, organization-scoped file route using non-guessable storage names.

Session cookies are HttpOnly, Secure in production, and SameSite-scoped; revoking a membership removes its active sessions.

Passwords are protected with one-way hashing and are not stored as readable plaintext.

Evidence uploads use a deny-by-default file allowlist, a 3 MB application limit, and byte-level format checks; executable, script, active web-file, and legacy binary Office formats are rejected.

Evidence can be archived reversibly, restored as Needs review, or permanently deleted with an explicit confirmation step.

Permanent evidence deletion removes the application record immediately and durably queues an unshared GrantProof-hosted file for deletion and retry; shared files remain until their final live reference is deleted, and external cloud links remain in the customer's storage.

Organization owners can permanently purge the organization, its application records, memberships, and GrantProof-hosted files after exact-name confirmation, password step-up, and fail-closed billing verification.

Security-relevant actions are recorded in the organization audit history where implemented.

The optional AI assistant treats customer-entered and document-derived content as untrusted evidence rather than instructions.

Application logging uses redaction rules for credentials, tokens, email addresses, notes, document text, and other sensitive fields.

GrantProof does not sell customer data or use customer records to train AI models.

Customer data controls

Archive is not deletion

GrantProof keeps reversible record management separate from irreversible deletion so customers can make an informed choice.

Archive and restore

Archive is reversible. Archived evidence is hidden from the normal Evidence Binder view, remains stored, and can be restored as Needs review.

Permanent document deletion

A separate confirmed action deletes the evidence record and its GrantProof-hosted stored file. External cloud links remain in the customer's own storage.

Organization deletion

Organization owners can permanently purge the organization's grants, evidence, findings, reports, memberships, and GrantProof-hosted files after typing the organization name.

Important boundaries

What GrantProof does not claim

GrantProof is not currently certified under SOC 2, HIPAA, FedRAMP, ISO 27001, PCI DSS, GDPR, or CCPA.
GrantProof does not currently offer a Business Associate Agreement. Do not upload Protected Health Information unless and until that changes in writing.
Multi-factor authentication and single sign-on are not part of this security baseline.
Tenant isolation is enforced through authenticated application and database queries on shared infrastructure rather than a separate database per customer.
The restored rate limiter is per-instance and in-memory, not a distributed rate-limit guarantee across every serverless instance.
GrantProof has not completed an independent third-party penetration test or security audit.
GrantProof has not published contractual recovery-time or recovery-point objectives.

Ask before uploading

Security and data-handling questions are welcome

GrantProof will answer with the controls and operational practices that are currently verified rather than inventing a certification, retention period, backup promise, or recovery objective.

Security contact

Contact GrantProof

Questions about access, deletion, storage, AI, vendors, or pilot limitations.

Email security contact