Security & Data Governance
Last updated: July 15, 2026
AutoGrant handles sensitive information about your organization, your funders, and your strategy. We take that seriously, and we'd rather tell you exactly what we do today than make claims we can't back up. This page is written for the people who run your IT and procurement review; send it to them as-is.
Where we are today
- Transport encryption. All traffic to and from the product runs over TLS 1.2+.
- At-rest encryption. Database and file storage are encrypted at rest using our cloud provider's managed keys.
- US data residency. All infrastructure runs in the United States by default.
- No training on your data. Your organization's data, documents, and strategy are never used to train AI models—ours or third parties'. We use commercial AI providers under agreements that prohibit training on customer content, and we don't sell or share what you put into AutoGrant.
- No cross-account learning. What AutoGrant learns from your past proposals—your voice, your track record, your funder history—stays in your instance. It is never used to inform any other organization's account.
- Least-privilege access. Production access is restricted to a small number of operators, scoped per task, and logged.
- Human-in-the-loop. AutoGrant never submits a proposal without your explicit sign-off, on any autonomy setting. The pre-submission checkpoint (we call it HC3 internally) is permanent and not configurable. See the diagram below.
How HC3 stays enforced
Every proposal moves from draft to portal through five separate checks. HC3, the pre-submission gate, is enforced in five places in the codebase. No autonomy setting can disable it.
AutoGrant never submits a proposal without your explicit sign-off, on any autonomy setting.
Your data: ownership and exit
- You own your data and outputs. Your documents, the proposals AutoGrant helps you draft, and everything derived from them belong to your organization.
- Leaving is clean. If you end your engagement, your data is exported to you in standard formats and deleted on request. No hostage files, no export fees.
- Hosted instances are dedicated. On hosted Enterprise engagements, your instance is dedicated to your organization; it is never shared with another customer.
Enterprise: run it in your own environment
For organizations whose data governance requires it, AutoGrant Enterprise deploys into your own cloud: AWS, Google Cloud, Azure, or a private/on-premises environment. In that model your documents never leave your environment, your identity and access controls apply, and your existing data-governance policies keep governing. The questions that stall shared-SaaS procurements mostly stop applying, because the answer to "where does our data live?" is: exactly where it lives now.
On every Enterprise engagement, your security and IT review is a named, scoped milestone in the pilot phase, planned with your team, not an obstacle discovered at contract time.
Working with your review process
- We'll complete your security questionnaire, including HECVAT for higher-education institutions, and answer follow-ups directly with your IT and procurement teams.
- Security documentation, including a current subprocessor list, is available on request (under NDA where appropriate).
- For funders, research-integrity offices, and program officers, we provide written documentation of the human-review process behind every application your team submits.
- We target WCAG 2.2 AA accessibility across the product and this site; accessibility conformance documentation is available on request.
What we don't claim
We're an early-stage company. We are not currently SOC 2, HIPAA, FedRAMP, or PCI certified. We don't claim compliance we haven't earned. If your organization needs a specific certification before working with us, raise it on the first call. We'll tell you honestly where we stand and what the path looks like—and for many requirements, the own-environment Enterprise deployment is the faster answer, because the system inherits the controls and attestations of your cloud rather than waiting on ours.
Responsible AI, in writing
AutoGrant is a signatory to the Fundraising.AI Framework for Responsible and Beneficial AI. Human control of every submission isn't our marketing; it's a standard we've publicly put our name to.
Reporting a vulnerability
If you believe you've found a security issue, please email chris@autogrant.ai with a description and steps to reproduce. We'll acknowledge within two business days and keep you in the loop on the fix.
Please give us a reasonable window to investigate and patch before public disclosure. We won't pursue good-faith researchers who follow responsible disclosure.
Subprocessors
AutoGrant runs on commercial cloud infrastructure and uses a small number of vendors for things like email delivery and analytics. A current list is available on request from chris@autogrant.ai.
Questions
Security questions from prospective customers are welcome and encouraged, before you've signed anything. Email chris@autogrant.ai and we'll get on a call, with your IT lead in the room if you want.
