SECURITY AND TRUST

Built for the one document a lab cannot afford to leak.

An unsubmitted proposal is unpublished research, an unfiled budget, and a competitive position in a single file. This page is what happens to yours: every system it touches, how long it stays, and what remains when the run ends.

DeletedYour proposal and files, the moment each review finishes — success or failure
Never trainedNot by us, and not by our model providers
EncryptedIn transit and at rest, by our hosting and storage providers
No card dataPayments go straight to Stripe; numbers never reach us
THE LIFECYCLE

What happens to your proposal, minute by minute.

Most vendors describe security as a list of adjectives. This is the actual path a file takes through GrantPanel, and the retention attached to each step.

  1. 01
    Upload

    The file is transferred over TLS and written to encrypted object storage, where it is held only while the run lasts. GrantPanel suggests revisions in your report; it never edits your proposal, and keeps no copy of it.

    TLS in transit · encrypted at rest
  2. 02
    Parse

    Text, structure, figure captions, and reference list are extracted in a worker whose only outbound calls are to our model providers and Semantic Scholar, the public literature index your references are checked against. Semantic Scholar receives the titles and DOIs of the works you cite, and nothing else from the proposal. The original file is not modified.

    Model providers · Semantic Scholar · nothing else
  3. 03
    Review

    The proposal is sent to our model providers — Anthropic and OpenAI, through their commercial APIs — under terms that exclude it from training and limit retention to a short abuse-monitoring window, typically up to 30 days. They receive the document as you submitted it, so any name or institution printed in it travels with it. They receive nothing from your account record: not your login, your email, or your purchase history.

    Not used for provider training · no account data
  4. 04
    Write

    Findings, deliberation, and consensus are assembled into your report and written to your account. This is the only artefact that outlives the run, and it belongs to you. Delete it from your Reviews page and its text is erased at once; what stays is a record that the run took place — its dates, the credit it used, and what it cost to run — kept with your billing history.

    Retained until you delete it
  5. 05
    Delete

    The uploaded files are deleted the moment the run ends, after the revision plan is prepared from them, whether the panel finished or failed. If a deletion fails, a scheduled sweep retries it until it succeeds.

    Automated · when the run ends · no manual step
  6. 06
    Confirm

    If you need to show a sponsored-programs office that a specific document is gone, ask and we will confirm in writing when that run was submitted and when its files fell inside the deletion schedule.

    Written confirmation on request
CONTROLS

The measures behind that lifecycle.

Limited access

Access to production data is limited to the operators who run the service, and it is not part of normal operation. Staff open a report only to answer your request or investigate a fault, and every opening is recorded in an append-only audit log. The stronger protection is structural: the files are gone once the review finishes, regardless of who could have reached them.

Tenant isolation

Every run is processed on its own, and every read and write is scoped to the account that owns it. One account's materials cannot be reached from another's run, and a run carries nothing from other accounts' runs.

Encryption

TLS for all traffic to and from the service. Object storage and the database are encrypted at rest by our providers, who manage the keys.

Automated deletion

Removing your files is automatic, not a person remembering to do it. It happens at the end of every run, finished or failed, and a scheduled sweep retries any deletion that fails, so nothing depends on the outcome or on anyone noticing.

Managed authentication

Sign-in runs through our identity provider rather than a credential store we operate, with Google SSO available. GrantPanel never holds your password.

Personnel

Bound by confidentiality and working to the handling rules on this page. The team is small, and every person with production access is named on request.

RETENTION

What we keep, and what we do not.

Retained
Your email address and account preferencesPurchase records and run entitlementsThe report: findings, deliberation, and the revision plan, which quotes the passages it would change. Kept until you delete itThe solicitation, for your proposal's 60-day revision window onlyMinimal operational and security logs
Not retained
Your proposal or supporting files, once the review finishesThe full extracted text of your proposalCard numbers — these go directly to StripeAny copy held for model training, ours or a provider's
POSTURE

Where we actually stand on certification.

Stated plainly, including the gaps. A vendor page that claims everything is a vendor page you cannot use in a security review.

FrameworkStatusDetail
SOC 2 Type IINot yetNo audit has been performed. We would rather say so here than let you discover it in week three of a procurement.
GDPR / UK GDPRSupportedData Processing Agreement published and countersignable. Standard Contractual Clauses for transfers on request.
HIPAANot coveredWe do not sign BAAs. Do not upload PHI. A narrative describing a clinical study is fine; the patient data behind it is not.
FedRAMP / CUINot coveredNot authorised for controlled unclassified information, ITAR, or export-controlled material.
Penetration testingNot yetNo third-party test has been commissioned. If your institution requires one before approval, tell us and we will schedule it rather than claim it.
FOR REVIEWERS OF THIS PAGE

Everything a security review usually asks for.

If you are an IT security team or a research-development office evaluating GrantPanel for your investigators, start here rather than with a questionnaire.

Need something not listed here?

We complete standard vendor security questionnaires — CAIQ, HECVAT, and institutional equivalents — and will provide our data-flow summary and our technical and organisational measures schedule. There is no audit report to send; the table above says why. Write to hello@grantpanel.ai and expect a reply within two business days.

DISCLOSURE

Found a vulnerability?

Report it to hello@grantpanel.ai. We acknowledge within one business day, keep you updated while we fix it, and will credit you publicly if you want the credit.

We will not pursue legal action against good-faith research that avoids privacy violations, service degradation, and access to data that is not your own. Please do not test with another researcher's proposal.