How we protect your data, proposals, and company information.
Last updated: September 6, 2026
SourceGent runs on cloud infrastructure whose providers hold SOC 2 Type II reports, with DDoS mitigation and web application firewall protection at the edge. SourceGent itself has not completed an independent SOC 2 audit; the certification is our providers', not ours, and we say so plainly. All traffic is encrypted in transit with TLS 1.3, and all data is encrypted at rest with AES-256. Uploaded documents live in private storage buckets: our servers read them directly, and the only links ever handed to a browser are short-lived signed URLs issued to authorized users. Company logos are the one exception, stored in a public bucket so they can render in your exported documents.
A document you upload follows one path, and every service on it is listed below.
These are the only third parties that process data on our behalf.
What happens to your data, in the order you are likely to ask.
Every piece of data in SourceGent is scoped to the authenticated user and their company. We enforce this at the database level using row-level security (RLS), not just in application code.
The optional review portal uses cryptographically random share tokens. Shared links expire automatically and are protected against brute-force enumeration. You can revoke any share link at any time from your account settings.
We use Anthropic's Claude API to analyze documents and generate proposal content. We take the following measures when handling AI processing:
If two users (or two tabs) save the same proposal section, or an AI regeneration finishes after a teammate saved, the conflict is detected and the later write is rejected with a notice rather than silently overwriting work. The rejected text stays in the editor as an unsaved draft so nothing is lost on either side.
In the event of a data breach that affects your personal information, we will notify affected users in accordance with applicable laws, including providing details about what was affected and steps taken to address the issue.
We welcome security researchers and users to report potential vulnerabilities. If you believe you have found a security issue in SourceGent, please report it to us before disclosing it publicly.
Report a vulnerability
Email us at security@sourcegent.io with a description of the issue, steps to reproduce, and potential impact. We will acknowledge your report within 48 hours and keep you updated as we investigate.
Please do not access or modify other users' data during testing, use automated scanners against production systems, or publicly disclose the issue before we have had a reasonable opportunity to address it.
We do not currently offer a bug bounty program, but we do acknowledge responsible disclosures and take every report seriously.
Have security questions that aren't answered here? Contact us: