Security
ProposalWorx.com uses technical and organizational controls designed to protect proposal data, account access and workspace separation.
Last updated: July 24, 2026
Hosting and infrastructure
ProposalWorx.com is built as a Nuxt web application and is designed to run on managed cloud hosting. Production infrastructure should be configured to serve the application over HTTPS only.
The application uses Supabase for authentication, database services and storage-oriented document workflows.
Encryption
- -Traffic should be encrypted in transit with HTTPS.
- -Supabase-managed services provide encryption controls for stored database and storage data.
- -ProposalWorx.com avoids exposing service role credentials to the browser.
Authentication
User authentication is handled through Supabase Auth. The application currently supports email based one-time passcodes for login and registration.
Protected product pages require an authenticated browser session before the user can access application data.
Roles and permissions
ProposalWorx.com uses organization workspaces with roles such as owner, admin, manager, member and viewer.
Server-side permission checks restrict sensitive actions such as billing, invitations, document archive operations and workspace administration.
Workspace separation
Customer records are scoped to organization workspaces. API handlers require an active organization context for workspace data requests.
Supabase row level security and server-side checks are used to help keep workspace data separated.
Backups and retention
Database and storage backup behavior depends on the configured Supabase project plan and operational settings.
Customer deletion and retention requests are handled according to the Privacy Policy, Data Processing Agreement and applicable legal obligations.
Data deletion
Workspace deletion requests can be sent to privacy@proposalworx.com. We may need to verify the requester and confirm workspace authority before deletion.
Deleted data may remain in backups, logs or legally required records for a limited period before normal retention processes remove it.
Logging and auditing
The application stores immutable activity records for important proposal and organization events.
Server errors are logged internally and sanitized before being returned to users.
Monitoring
ProposalWorx.com may use application logs, uptime checks, performance telemetry and error monitoring to detect reliability and security issues.
Monitoring data is used to investigate incidents, improve service stability and protect the platform.
AI providers
Optional AI features may use third party AI providers to analyze RFPs, summarize requirements or assist with opportunity review.
Customer content submitted to AI features is processed to provide the requested feature. Users should avoid sending content to AI features unless they are authorized to process it.
Third party providers
ProposalWorx.com may rely on providers for hosting, authentication, database, storage, payments, email, analytics, monitoring, AI and integrations.
A subprocessor summary is available on the Subprocessors page and should be reviewed for current provider categories.
Incident response
If ProposalWorx.com identifies a security incident affecting customer data, the team will investigate, contain the issue, assess the impact and communicate with affected customers as required by law and contract.
Customers should report suspected security issues promptly through security@proposalworx.com.
Vulnerability reporting
Reports should include the affected URL or feature, reproduction steps, the potential impact and a safe proof of concept where possible.
Do not attempt to access data that does not belong to you, disrupt service availability or use automated scanning that could affect other users.