This page is maintained by ProposalIQ AI to answer common security questions about how the platform handles your solicitation, evidence, and analysis data. It is not a certification statement.
Every workspace table — analyses, evidence, requirements, uploads — is scoped to your organization at the database level. Row-level security policies enforce that at every query. No cross-tenant reads.
Uploaded solicitations (PDF/DOCX) are stored in authenticated, non-public storage. Documents are not indexed to public URLs.
Email/password and Google OAuth are supported. Sessions are managed by our authentication provider (Supabase Auth) with short-lived tokens.
Solicitation and evidence text is not used to train foundation models. When live AI analysis is enabled, extractions are sent to your configured provider for the duration of the analysis run and are not retained by ProposalIQ AI for training.
Members belong to an organization with defined roles. Elevated actions are gated server-side, not by client UI state alone.
ProposalIQ AI provides the platform controls above. Customers are responsible for managing their own user accounts, keeping credentials confidential, and reviewing AI output before making bid decisions. We do not represent that the tool itself carries FedRAMP, FAR, or other regulatory certifications.