Skip to content
GGrantComply

Security & Privacy

Your data is protected. Full stop.

GrantComply was built for organizations handling sensitive funding data — which means security and data isolation aren't afterthoughts. Here's exactly how we protect your information.

Complete data isolation

Your organization's data is never visible to any other organization — ever.

Bank-grade encryption

AES-256 encryption at rest. TLS 1.3 in transit. Industry-standard protection.

SOC 2 infrastructure

Hosted on AWS via Supabase — SOC 2 Type 2 certified cloud infrastructure.

Verified access

Organization email domains verified. All other accounts manually reviewed.

Data isolation — how it works

Every organization in GrantComply operates in a completely isolated data environment enforced at the database level using Row Level Security (RLS) — the same technology used by financial institutions to separate customer accounts. This means:

  • Organization A can never see Organization B's data — not grants, not projects, not documents, not anything
  • Even GrantComply staff cannot access your data without explicit audit logging
  • Data isolation is enforced by the database itself — not just application logic
  • There is no configuration error or bug that could expose your data to another organization
Think of it like separate safe deposit boxes at a bank. The bank operates the vault, but only you hold the key to your box. We operate the platform, but only your organization can access your data.

Have a security question or need documentation for a procurement review? Contact us at hello@grantcomply.app.