Security and Compliance

Your proposal data is not our training data

Encryption at every layer. Tenant isolation at the database level. Zero AI model training on customer content. Here is exactly what we do and what we are working toward.

What is live today

Security measures

Encryption everywhere

All data encrypted at rest (AES-256) and in transit (TLS 1.3). Database-level encryption via Supabase/PostgreSQL. No unencrypted data at any point in the pipeline.

Tenant isolation

Row-level security (RLS) enforced at the database layer. Every query is scoped to your organization. One tenant cannot access another tenant's data, period.

No AI model training on your data

Your proposals, company profiles, and bid intelligence are never used to train AI models. We use the Anthropic API with zero-retention data processing. Your data stays yours.

US-based infrastructure

Application runs on Vercel edge network with US-region deployment. Database hosted on Supabase with US-region PostgreSQL. No data leaves US infrastructure.

Role-based access control

Granular permissions per workspace. Admin, editor, and viewer roles. Control who can create proposals, manage company profiles, and access bid intelligence.

Audit logging

Every significant action is logged: proposal creation, data exports, team member changes, and configuration updates. Full audit trail for compliance requirements.

Compliance roadmap

Where we are and where we are headed

We are honest about what is live, what is in progress, and what is planned. No vaporware claims.

Data encryption (at rest + in transit)

Live

AES-256 at rest, TLS 1.3 in transit. Active since day one.

Live

Row-level security / tenant isolation

Live

Enforced at the PostgreSQL layer via Supabase RLS policies. Every query is scoped.

Live

Role-based access control

Live

Admin, editor, viewer roles with granular workspace permissions.

Live

Zero-retention AI data processing

Live

Anthropic API does not retain inputs or outputs. Your proposal content is not stored by the AI provider.

Live

SOC 2 Type II certification

Planned

Formal audit engagement planned. Covers security, availability, and confidentiality trust service criteria.

Q4 2026

FedRAMP authorization

Roadmap

Required for federal agencies with moderate or high impact data. Working toward authorization through a sponsoring agency.

2027

CMMC Level 2 alignment

Roadmap

For contractors handling Controlled Unclassified Information (CUI). Aligning controls to NIST SP 800-171.

On roadmap

Data handling

Common questions about your data

What data does Caprix AI store?

Your company profile (NAICS codes, certifications, personnel), proposals you create, bid pipeline data, and contract tracking information. We store what you enter, nothing more.

Is my proposal content sent to AI models?

Yes, when you use AI features (proposal drafting, self-scoring, RFP chat). The content is sent to the Anthropic API for processing. Anthropic does not retain inputs or outputs and does not use them for model training.

Can other tenants see my data?

No. Row-level security is enforced at the database layer. Every query includes your organization ID as a mandatory filter. There is no application-level workaround that could bypass this.

Where are backups stored?

Supabase provides automated daily backups stored in the same US region as your primary database. Point-in-time recovery is available.

Can I export or delete my data?

Yes. You can export your full dataset at any time. If you cancel your account, we delete all your data within 30 days. No data is retained after deletion.

Questions about security?

We are happy to walk through our security practices in detail. Reach out and we will schedule a call.