Trust & Safety

Security at SourceGent

How we protect your data, proposals, and company information.

Last updated: September 6, 2026

Encrypted in Transit
TLS 1.3 everywhere
Encrypted at Rest
AES-256 encryption
Row-Level Security
Database-enforced isolation
Rate Limited
Per-endpoint AI limits

Infrastructure & Hosting

SourceGent runs on cloud infrastructure whose providers hold SOC 2 Type II reports, with DDoS mitigation and web application firewall protection at the edge. SourceGent itself has not completed an independent SOC 2 audit; the certification is our providers', not ours, and we say so plainly. All traffic is encrypted in transit with TLS 1.3, and all data is encrypted at rest with AES-256. Uploaded documents live in private storage buckets: our servers read them directly, and the only links ever handed to a browser are short-lived signed URLs issued to authorized users. Company logos are the one exception, stored in a public bucket so they can render in your exported documents.

How Your Data Moves

A document you upload follows one path, and every service on it is listed below.

  1. Upload. The file lands in private storage on Supabase, encrypted at rest, scoped to your company.
  2. Extraction. Our servers parse the file into text. Nothing leaves our infrastructure for this step.
  3. AI processing. The extracted text, your approved company knowledge, and your instructions are sent to Anthropic's Claude API over TLS for analysis or drafting. We operate under Anthropic's commercial API terms, which prohibit training on API inputs without explicit opt-in.
  4. Storage. The results (analysis, requirements, draft sections) are written back to your company's rows in the database, behind row-level security.
  5. Indexing. The opportunity analysis (summary, requirements, evaluation criteria, win themes) and your approved knowledge items, including quoted passages from your documents, are sent to Voyage AI over TLS to be converted into embedding vectors, which are stored in your company's rows and used to find relevant knowledge when drafting.
  6. Export. DOCX and PDF files are generated on demand and streamed to you; we do not keep a copy of the exported file, only a record that an export happened.

Subprocessors

These are the only third parties that process data on our behalf.

  • Supabase: Database, authentication, and file storage. Stores your account data, proposals, and uploaded files.
  • Anthropic (Claude): AI language model processing. Analyzes documents and generates proposal content.
  • Voyage AI (MongoDB): Text embeddings. Converts approved company knowledge (including quoted passages from your documents) and opportunity analyses (summary, requirements, evaluation criteria, win themes) into vectors for semantic retrieval.
  • Stripe: Payment processing. Handles subscription billing; we never store raw card data.
  • Vercel: Cloud hosting and deployment. Hosts the application and serves web traffic.
  • Resend: Email delivery. Sends transactional emails (verification, billing, alerts).
  • PostHog: Product analytics. Tracks usage events tied to your account (user id and email) to improve the product.
  • Sentry: Error monitoring. Captures application errors for debugging.
  • Crisp: Customer support chat. Powers the in-app support widget.
  • SAM.gov / USASpending.gov / Grants.gov / GSA CALC: Government data APIs. Imports opportunity data, past award history, and market rate benchmarks (public data); receives the search terms we send, such as NAICS codes, partner identifiers, and labor category names.

Data Retention & Deletion

What happens to your data, in the order you are likely to ask.

  • While you use the product: proposals, opportunities, sections, uploads, and knowledge items are kept until you delete them. No automated job ever removes them.
  • If you cancel: the account moves to the Free plan. Your content stays in place; export is a paid-plan feature, so export before the period ends or re-subscribe to export later.
  • If you delete your account: deletion runs immediately, in the same request, removing your proposals, opportunities, uploaded files, company profiles, knowledge items, and login. One audit record of the deletion itself is written. Deletion is refused while you still own a company that has other team members, so that their work is not removed with yours; transfer ownership first.
  • Housekeeping: a weekly job prunes telemetry only: per-call AI usage records after about 13 months and quota events after about 24 months, and cached opportunity listings you never imported after 180 days. A daily job prunes pricing drafts that were never approved and untouched for 90 days, and expired AI pricing suggestions.

Data Isolation

Every piece of data in SourceGent is scoped to the authenticated user and their company. We enforce this at the database level using row-level security (RLS), not just in application code.

What This Means

  • Your proposals, documents, and company profile are never visible to other users
  • Multi-company accounts enforce company-level isolation: Company A cannot access Company B data
  • Team members only see data scoped to the companies they have been explicitly invited to
  • RLS policies are enforced at the database query layer, providing defense-in-depth even if application code has a bug

Proposal Sharing

The optional review portal uses cryptographically random share tokens. Shared links expire automatically and are protected against brute-force enumeration. You can revoke any share link at any time from your account settings.

Authentication & Access Control

  • Passwords are protected with industry-standard hashing: we never store plaintext passwords
  • Email verification is required before accessing AI features
  • Sessions use secure, HTTP-only cookies with short-lived credentials
  • All authenticated routes are protected server-side; client-side guards are defense-in-depth only
  • Team invitations expire and are single-use; they cannot be redeemed by unintended recipients
  • Multi-factor authentication is not yet offered. Sign in with Google is available if your organization enforces MFA there
  • Account deletion is immediate and self-service; see Data Retention & Deletion above for exactly what is removed

AI Processing Security

We use Anthropic's Claude API to analyze documents and generate proposal content. We take the following measures when handling AI processing:

Data in Transit to Anthropic

  • All API calls to Anthropic are made over HTTPS/TLS
  • We operate under Anthropic's commercial API terms, which prohibit training on API inputs without explicit opt-in
  • Your document content is never shared with other SourceGent users or organizations
  • We do not use your proposals or documents to fine-tune or train any AI model

AI Usage Controls

  • Per-endpoint rate limiting and daily cost caps protect against abuse
  • Usage budgets fail closed: if usage cannot be verified, AI requests are denied rather than allowed to run uncapped
  • Every AI call is logged for quota tracking and anomaly detection
  • Feature access checks fail closed: an error during an access check denies access, never grants it

What Not to Upload

Important: SourceGent is not FedRAMP authorized and is not an accredited system for regulated government data. Do not upload:
  • Controlled Unclassified Information (CUI) or anything marked FOUO, or export-controlled technical data (ITAR, EAR)
  • Classified material of any level
  • Personally identifiable information subject to federal privacy rules (for example, beneficiary or patient records)
  • Payment card numbers, government ID numbers, or credentials
Public solicitations, your own past performance, capability statements, resumes with consent, and pricing worksheets are the data the product is built for. If you are not sure whether a document is in scope, ask your compliance team before uploading it.

Application Security

Input Validation & File Handling

  • Uploaded files are validated by their content, not just their filename or extension
  • Files are stored in isolated storage buckets, never served from the web root
  • All user-supplied input is validated and sanitized server-side

Request Security

  • Content Security Policy (CSP) headers on all responses
  • Cross-origin access is restricted to authorized domains only
  • Internal and scheduled endpoints require authentication; nothing is open by default

Auditing & Administrative Access

  • Sensitive actions (exports, sharing, cancellation, account deletion) are recorded in an audit log that is append-only at the database level
  • Administrative access is limited to named staff accounts and enforced server-side; inside a customer account, what a person can do is governed by their team role

Your Draft Is Not Lost

  • Every save is confirmed by the server before the editor reports it saved. A failed save keeps your text on screen, retries once automatically on a network or server error, and offers a one-click retry
  • Unsaved text is also written to your browser's local storage as you type, so a crash, a reload, or a closed tab does not lose it; the editor offers it back the next time the section opens
  • Exporting saves any unsaved edits first, so the file you download matches what you see

Concurrent Editing Protection

If two users (or two tabs) save the same proposal section, or an AI regeneration finishes after a teammate saved, the conflict is detected and the later write is rejected with a notice rather than silently overwriting work. The rejected text stays in the editor as an unsaved draft so nothing is lost on either side.

Billing & Payment Security

  • All payments are processed by Stripe, a PCI DSS Level 1 certified payment processor
  • We never store, transmit, or log raw credit card numbers or CVV codes
  • Every payment event is cryptographically verified and matched to your account before any subscription change is applied
  • Subscription state is independently reconciled on a regular schedule, so billing status stays accurate even if an individual event is missed

Monitoring & Incident Response

  • Error monitoring: Application exceptions are captured and triaged in real time
  • Performance monitoring: Latency and error rates are tracked continuously
  • Dependency updates: We monitor and apply security patches to our dependency tree on a regular basis

In the event of a data breach that affects your personal information, we will notify affected users in accordance with applicable laws, including providing details about what was affected and steps taken to address the issue.

Responsible Disclosure

We welcome security researchers and users to report potential vulnerabilities. If you believe you have found a security issue in SourceGent, please report it to us before disclosing it publicly.

Report a vulnerability

Email us at security@sourcegent.io with a description of the issue, steps to reproduce, and potential impact. We will acknowledge your report within 48 hours and keep you updated as we investigate.

Please do not access or modify other users' data during testing, use automated scanners against production systems, or publicly disclose the issue before we have had a reasonable opportunity to address it.

We do not currently offer a bug bounty program, but we do acknowledge responsible disclosures and take every report seriously.

Security Questions

Have security questions that aren't answered here? Contact us:

Digital Dreamsmiths LLC
Security inquiries: security@sourcegent.io
General support: support@sourcegent.io
Terms of ServicePrivacy PolicyBack to Home