How we handle your data
Your solicitations, past performance and pricing can be sensitive. This page says plainly how RFPeasy handles them.
We have not pursued security certifications for RFPeasy itself. Instead, every statement below is something our code does today, or something one of our vendors publishes about itself, named as theirs.
Your workspace is walled off
Our server code scopes your requests to the workspace you are signed in to, and sessions you keep personal stay personal, even from teammates in the same workspace.
Consultants who manage several client companies can give a client their own login. That login sees only its own company's folders, documents, outputs and library, plus what it created.
Row-level security rules on our database tables protect direct database access, and automated tests check that one workspace cannot read another's data.
Two-factor sign-in
Every account can turn on two-factor sign-in with an authenticator app. Once it is on, our servers require the second factor on your requests, not just at the sign-in page.
Recovery codes are stored only as one-way hashes, and recovery attempts are rate limited.
Encrypted in transit and at rest
Every connection to RFPeasy is served over HTTPS (TLS), and browsers are told to use HTTPS only (HSTS).
Your data is stored with Supabase, our database provider. Supabase states that "All customer data is encrypted at rest with AES-256 and in transit via TLS." See supabase.com/security.
AI analysis runs on our servers
All AI processing happens server-side. The keys that talk to our AI provider live only on our servers and are never sent to your browser. Your documents are analyzed to produce your outputs: compliance matrices, drafts and analyses.
We use Anthropic's API for that analysis. Anthropic states that by default it does not use inputs or outputs from its commercial products, including the API, to train its models. Read their policy: Is my data used for model training?.
A checkpoint before sensitive uploads
Before you upload a solicitation or import files into your library, you must acknowledge a CUI / FOUO notice. It is a checkbox you actively confirm, and you cannot continue until you do.
RFPeasy is built for publicly available solicitations, such as those on SAM.gov and agency websites. Do not upload classified material or Controlled Unclassified Information (CUI).
Payments never touch our servers
Billing runs on Stripe. You enter card details on Stripe's own pages; RFPeasy stores only the Stripe reference numbers for your subscription, never your card number.
Stripe states it is certified to PCI Service Provider Level 1, "the most stringent level of certification available in the payments industry." See docs.stripe.com/security.
Your saved signature is yours alone
If you save a signature for bid packets, it is stored in private storage under your own account. Only you can use it, and it is shown through a link that expires after two minutes.
Usage limits and logging
We enforce usage quotas and keep a log of expensive operations: which feature ran, the AI model, token counts, cost and time. The log exists for abuse prevention and accurate billing.
You can leave on your own terms
You can cancel your subscription yourself, any time, from the Pricing page or your Account billing settings. No email, no phone call.
When you delete your account, you have 30 days to change your mind. After that we cancel any active subscription and permanently delete your account, your personal records, your workspace memberships, any workspace where you are the only member, and your saved signature.
Who we rely on
RFPeasy runs on established providers. Their certifications are theirs, not RFPeasy's:
- Vercel hosts the application. Vercel states it has a SOC 2 Type 2 attestation and ISO 27001 certification (vercel.com/security).
- Supabase provides our database, file storage and sign-in. Supabase states it is SOC 2 Type 2 compliant and ISO 27001 certified (supabase.com/security).
- Stripe processes payments, PCI Service Provider Level 1 per Stripe (docs.stripe.com/security).
- Anthropic provides the AI models. Anthropic lists SOC 2 Type I and Type II, ISO 27001:2022 and ISO/IEC 42001:2023 (trust.anthropic.com).
- Resend sends our email, Sentry reports application errors, and PostHog measures product usage.
What we don't do
- We do not sell your personal information.
- We do not train AI on your documents.
- We do not claim certifications we do not hold.
Questions?
Security questions, or something you think we should look at? Email us and a person will answer. info@govaccesssolutions.com
Read the full Privacy Policy and Data Processing Addendum.