Your data deserves serious protection

Your proposals contain sensitive business data. We take your privacy and security seriously. Here’s how we protect your information at every level.

How we protect your data

Multiple layers of security working together to keep your business information safe.

Data Encryption

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Your proposals and business data are protected at every stage.

Access Control

Role-based permissions ensure team members only access what they need. Workspaces are fully isolated, your data is never visible to other organizations.

Authentication Security

Passwords are hashed using industry-standard algorithms. Two-factor authentication (2FA) is available for all accounts. Sessions expire automatically after inactivity.

GDPR Compliance

We process data in accordance with EU regulations. We practice data minimization, support the right to erasure, and never sell your data to third parties.

Infrastructure

Our platform runs on modern, managed cloud infrastructure with automated backups, uptime monitoring, and redundancy. We continuously monitor for anomalies.

Payment Security

Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. We never store credit card numbers or sensitive payment data on our servers.

Security across every feature

From the moment you create a proposal to the final signature, every feature is built with security in mind.

Input Validation & Sanitization

Every API endpoint validates and sanitizes input to prevent injection attacks. We apply strict type checking, length limits, and content filtering across the entire application.

Rate Limiting & Abuse Prevention

All endpoints are rate-limited to prevent brute-force attacks and API abuse. Sensitive operations like login, signature verification, and password reset have additional restrictive limits.

Secure CRM Integrations

CRM integrations use OAuth 2.0 with PKCE where supported. Tokens are encrypted at rest and automatically refreshed. Connection state is verified on every request.

API Key Management

API keys are stored using one-way hashing. Each key has configurable usage quotas, automatic expiry, and per-request audit logging. Keys can be revoked instantly.

CORS & Origin Protection

Cross-origin requests are restricted to authorized domains only. Production environments enforce strict origin policies, preventing unauthorized access from external sites.

Security Audits & Code Reviews

We perform regular security audits of our codebase, dependencies, and infrastructure. All changes go through code review before deployment.

Secure Proposal Sharing

Shared proposals use unique, non-guessable tokens. Optional password protection and access expiry are available. All viewing activity is tracked and visible to the sender.

E-Signature Security

Electronic signatures are verified via email-based authentication with one-time codes. Each signature captures consent metadata, timestamp, and IP address for legal compliance.

What data do we store?

We believe in transparency. Here's exactly what data we collect and how we use it.

Account Data

Name, email address, hashed password, profile settings, 2FA configuration

Proposal Data

Proposal content, pricing tables, templates, media uploads, version history

Sharing & Analytics

Share tokens, viewing activity (page views, time spent), signature records, follow-up history

Integration Data

Encrypted CRM tokens, field mappings, synced deal data. We only access CRM data you explicitly authorize.

Billing Data

Subscription plan, Stripe customer ID, invoice history. Payment details are stored exclusively by Stripe.

How we protect your privacy

Privacy is a core value, not just a checkbox. We designed our platform with privacy as the starting point.

Ready to get started?

Your data security is our priority. Start building professional proposals with confidence.