Trust & security
How we protect your data
This page is maintained by the Proposably team to answer common security, privacy, and compliance questions about the service. It reflects the controls in place today and is updated as our program matures.
This is app-owned content, not an independent certification. If you need our full controls under NDA, contact security@proposably.com.
Last reviewed: July 18, 2026
Access & authentication
Every account is authenticated through email + password or Google sign-in. Passwords are hashed by our identity provider using industry-standard algorithms; we never see or store your plaintext password.
Staff access to your data is scoped by role. Roles are stored in a dedicated permissions table, checked server-side on every request, and audited when they change. Only accounts with the admin role can modify pricing, users, or system configuration.
We recommend all staff enable multi-factor authentication. Enforcement across every admin account is on our roadmap.
Platform & hosting
Proposably runs on managed cloud infrastructure with SOC 2 Type II certified underlying providers. Application code runs at edge locations for low latency and is isolated per-request.
Our database enforces row-level security on every table: no query reaches your data unless a policy explicitly allows it, and permissions are re-checked on every read and write.
Data collection & retention
We collect only what is needed to deliver procurement setup: your business identity, contact details, capability statements, and the documents you upload for supplier registrations. We do not sell or share your data for marketing.
Uploaded documents are stored in private buckets scoped to your session or order. Public access requires a short-lived signed URL. We do not currently store any Protected Health Information (PHI); healthcare-regulated workloads require additional agreements that we have not yet signed.
Order records are retained for the life of the account plus 7 years to satisfy typical Canadian records-retention expectations. You can request earlier deletion (see below).
Encryption
All traffic to and from Proposably is served over TLS 1.2 or higher; older protocols are refused. HTTP requests are automatically upgraded to HTTPS.
Data at rest is encrypted by our cloud provider using AES-256. Backup snapshots inherit the same encryption.
Subprocessors
The following third parties process data on our behalf:
- Lovable Cloud (Supabase) - database, authentication, storage, edge functions.
- Stripe - payment processing. We never see or store your full card number.
- Resend - transactional email delivery (order updates, receipts, info requests).
- Lovable AI Gateway - occasional AI-assisted content generation. No customer PII or PHI is sent through this path.
We notify existing customers before adding a new subprocessor with access to customer data.
Incident & vulnerability reporting
If you believe you have found a security issue, please email security@proposably.com. We acknowledge reports within 3 business days and coordinate disclosure timing with the reporter.
In the event of a confirmed breach affecting customer data, we notify affected customers without undue delay and no later than the timelines required by applicable privacy law in their jurisdiction.
Compliance status
Proposably follows SOC 2-aligned practices - documented access controls, audit logging, change management, and vendor review - and we can share our current control summary under NDA. We are not SOC 2 Type II certified today; a formal audit is on our roadmap and driven by customer demand.
HIPAA: we do not currently accept Protected Health Information (PHI). Healthcare customers requiring a Business Associate Agreement should contact us before onboarding so we can confirm the required subprocessor agreements are in place.
Requesting your data or deletion
You can request a copy of the data we hold about you, corrections to inaccurate records, or deletion of your account by emailing privacy@proposably.comfrom the address on file. We respond within 30 days.
For legal or compliance reasons (tax records, active procurement obligations) some records may be retained beyond your deletion request; we will tell you which categories those are and when they will be removed.
Shared responsibility. The controls above cover what Proposably runs. Customers are responsible for keeping their own login credentials secure, controlling who they invite as staff, and ensuring the data they upload is theirs to share.
Have questions we didn't cover? See the FAQ or email security@proposably.com.