Security
How we protect accounts and proposal data today. We do not claim a SOC 2 report.
In transit
The app is served over HTTPS. Data between your browser and the service is encrypted in transit.
Sign-in
Accounts are handled by Clerk. We do not store your password. Access to the dashboard, proposals, settings, services, and templates requires a signed-in session.
Storage
Application data lives in a Neon Postgres database. That includes workspace profiles, pasted inquiries, proposals, private notes, view events, services, and templates.
What clients can see
A shared proposal link shows the client-facing document. Private notes are not included on that view. Anyone with the link can open it, so treat the link like a document you meant to send.
What we do not claim
We have not completed a SOC 2 audit. If you need a formal report for a client, email fawadalidev9918@gmail.com.