Your proposal data is not our training data
Encryption at every layer. Tenant isolation enforced in our application, backed by database-level policies. Zero AI model training on customer content. Here is exactly what we do and what we are working toward.
What is live today
Security measures
Encryption everywhere
All data encrypted at rest (AES-256) and in transit (TLS 1.3). Database-level encryption via Supabase/PostgreSQL. No unencrypted data at any point in the pipeline.
Tenant isolation
Every request is scoped to your organization in our application layer, and core data tables (proposals, RFPs, contracts, company profiles, and more) carry database-level row-level security policies as an additional backstop.
No AI model training on your data
Your proposals, company profiles, and bid intelligence are never used to train AI models. We use the Anthropic API with zero-retention data processing. Your data stays yours.
US-based infrastructure
Application runs on Vercel edge network with US-region deployment. Database hosted on Supabase with US-region PostgreSQL. No data leaves US infrastructure.
Role-based access control
Granular permissions per workspace. Admin, editor, and viewer roles. Control who can create proposals, manage company profiles, and access bid intelligence.
Human-in-the-loop review
Built-in proposal review workflow (blue, pink, red, gold, and final team stages) with timestamped comments, so nothing generated by the platform ships without a human checkpoint your team controls.
Compliance roadmap
Where we are and where we are headed
We are honest about what is live, what is in progress, and what is planned. No vaporware claims.
Data encryption (at rest + in transit)
LiveAES-256 at rest, TLS 1.3 in transit. Active since day one.
Tenant isolation
LiveEnforced primarily at the application layer via mandatory organization-scoped queries, with Supabase row-level security policies on core data tables as an additional layer.
Full database-level audit logging
RoadmapStructured, queryable audit trail for account changes, data exports, and configuration updates across the platform. Not yet built.
Role-based access control
LiveAdmin, editor, viewer roles with granular workspace permissions.
Zero-retention AI data processing
LiveAnthropic API does not retain inputs or outputs. Your proposal content is not stored by the AI provider.
SOC 2 Type II certification
PlannedFormal audit engagement planned. Covers security, availability, and confidentiality trust service criteria.
FedRAMP authorization
RoadmapRequired for federal agencies with moderate or high impact data. Working toward authorization through a sponsoring agency.
CMMC Level 2 alignment
RoadmapFor contractors handling Controlled Unclassified Information (CUI). Aligning controls to NIST SP 800-171.
Data handling
Common questions about your data
What data does Caprix AI store?
Your company profile (NAICS codes, certifications, personnel), proposals you create, bid pipeline data, and contract tracking information. We store what you enter, nothing more.
Is my proposal content sent to AI models?
Yes, when you use AI features (proposal drafting, self-scoring, RFP chat). The content is sent to the Anthropic API for processing. Anthropic does not retain inputs or outputs and does not use them for model training.
Can other tenants see my data?
No. Every query in our application includes your organization ID as a mandatory filter, and core data tables additionally carry database-level row-level security policies. We're extending that database-level enforcement across the remaining tables as part of our ongoing security work.
Where are backups stored?
Supabase provides automated daily backups stored in the same US region as your primary database. Point-in-time recovery is available.
Can I export or delete my data?
Yes. You can export your full dataset at any time. If you cancel your account, we delete all your data within 30 days. No data is retained after deletion.