Your data. Your grants. Our responsibility.
Grant applications contain sensitive organizational information. We take that trust seriously — with enterprise-grade security, transparent practices, and documentation available on request.
Security documentation is available on request at security@grantable.co
Where our audit stands
Our most recent SOC 2 Type II examination covered April 9 – July 9, 2025. We are currently selecting a new independent audit firm for our next examination, and we do not claim an active certification while that work is in progress. The controls below are in place today.
For a security questionnaire, our signed policies, or a written description of how we handle your data, email security@grantable.co.
Our security commitments.
Signed security policies
Our information security, vendor management, and CISO policies are documented, signed, and reviewed on a regular cadence. Copies are available to customers and prospects on request.
Encryption everywhere
All data is encrypted in transit (TLS 1.2+) and at rest. Your documents, grant applications, and organizational data are protected at every layer.
No AI training on your data
Your content is never used to train AI models — ours or anyone else's. Our AI providers (Anthropic, OpenAI) are contractually prohibited from training on customer data.
Secure infrastructure
Built on trusted cloud infrastructure with role-based access controls, regular security assessments, and automated monitoring for potential threats.
Data minimization
When using AI features, we send only the minimum necessary context to our providers. Your full database is never transmitted — just the relevant portions needed for each request.
Your data, your control
Access, export, or delete your data at any time. We don't hold your data hostage — if you leave, your data goes with you.
Transparency resources.
Everything you need to evaluate our security posture.