Security

This page is maintained by ProposalIQ AI to answer common security questions about how the platform handles your solicitation, evidence, and analysis data. It is not a certification statement.

Tenant isolation via row-level security

Every workspace table — analyses, evidence, requirements, uploads — is scoped to your organization at the database level. Row-level security policies enforce that at every query. No cross-tenant reads.

Private document storage

Uploaded solicitations (PDF/DOCX) are stored in authenticated, non-public storage. Documents are not indexed to public URLs.

Authentication

Email/password and Google OAuth are supported. Sessions are managed by our authentication provider (Supabase Auth) with short-lived tokens.

Responsible data use

Solicitation and evidence text is not used to train foundation models. When live AI analysis is enabled, extractions are sent to your configured provider for the duration of the analysis run and are not retained by ProposalIQ AI for training.

Access controls

Members belong to an organization with defined roles. Elevated actions are gated server-side, not by client UI state alone.

Shared responsibility

ProposalIQ AI provides the platform controls above. Customers are responsible for managing their own user accounts, keeping credentials confidential, and reviewing AI output before making bid decisions. We do not represent that the tool itself carries FedRAMP, FAR, or other regulatory certifications.

Security contact: security@proposaliqai.com
Start Free Analysis