Your proposals contain sensitive business data. We take your privacy and security seriously. Here’s how we protect your information at every level.
Multiple layers of security working together to keep your business information safe.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Your proposals and business data are protected at every stage.
Role-based permissions ensure team members only access what they need. Workspaces are fully isolated, your data is never visible to other organizations.
Passwords are hashed using industry-standard algorithms. Two-factor authentication (2FA) is available for all accounts. Sessions expire automatically after inactivity.
We process data in accordance with EU regulations. We practice data minimization, support the right to erasure, and never sell your data to third parties.
Our platform runs on modern, managed cloud infrastructure with automated backups, uptime monitoring, and redundancy. We continuously monitor for anomalies.
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We never store credit card numbers or sensitive payment data on our servers.
From the moment you create a proposal to the final signature, every feature is built with security in mind.
Every API endpoint validates and sanitizes input to prevent injection attacks. We apply strict type checking, length limits, and content filtering across the entire application.
All endpoints are rate-limited to prevent brute-force attacks and API abuse. Sensitive operations like login, signature verification, and password reset have additional restrictive limits.
CRM integrations use OAuth 2.0 with PKCE where supported. Tokens are encrypted at rest and automatically refreshed. Connection state is verified on every request.
API keys are stored using one-way hashing. Each key has configurable usage quotas, automatic expiry, and per-request audit logging. Keys can be revoked instantly.
Cross-origin requests are restricted to authorized domains only. Production environments enforce strict origin policies, preventing unauthorized access from external sites.
We perform regular security audits of our codebase, dependencies, and infrastructure. All changes go through code review before deployment.
Shared proposals use unique, non-guessable tokens. Optional password protection and access expiry are available. All viewing activity is tracked and visible to the sender.
Electronic signatures are verified via email-based authentication with one-time codes. Each signature captures consent metadata, timestamp, and IP address for legal compliance.
We believe in transparency. Here's exactly what data we collect and how we use it.
Name, email address, hashed password, profile settings, 2FA configuration
Proposal content, pricing tables, templates, media uploads, version history
Share tokens, viewing activity (page views, time spent), signature records, follow-up history
Encrypted CRM tokens, field mappings, synced deal data. We only access CRM data you explicitly authorize.
Subscription plan, Stripe customer ID, invoice history. Payment details are stored exclusively by Stripe.
Privacy is a core value, not just a checkbox. We designed our platform with privacy as the starting point.
Your data security is our priority. Start building professional proposals with confidence.