Access to production data is limited to the operators who run the service, and it is not part of normal operation. Staff open a report only to answer your request or investigate a fault, and every opening is recorded in an append-only audit log. The stronger protection is structural: the files are gone once the review finishes, regardless of who could have reached them.
Built for the one document a lab cannot afford to leak.
An unsubmitted proposal is unpublished research, an unfiled budget, and a competitive position in a single file. This page is what happens to yours: every system it touches, how long it stays, and what remains when the run ends.
What happens to your proposal, minute by minute.
Most vendors describe security as a list of adjectives. This is the actual path a file takes through GrantPanel, and the retention attached to each step.
- 01Upload
The file is transferred over TLS and written to encrypted object storage, where it is held only while the run lasts. GrantPanel suggests revisions in your report; it never edits your proposal, and keeps no copy of it.
- 02Parse
Text, structure, figure captions, and reference list are extracted in a worker whose only outbound calls are to our model providers and Semantic Scholar, the public literature index your references are checked against. Semantic Scholar receives the titles and DOIs of the works you cite, and nothing else from the proposal. The original file is not modified.
- 03Review
The proposal is sent to our model providers — Anthropic and OpenAI, through their commercial APIs — under terms that exclude it from training and limit retention to a short abuse-monitoring window, typically up to 30 days. They receive the document as you submitted it, so any name or institution printed in it travels with it. They receive nothing from your account record: not your login, your email, or your purchase history.
- 04Write
Findings, deliberation, and consensus are assembled into your report and written to your account. This is the only artefact that outlives the run, and it belongs to you. Delete it from your Reviews page and its text is erased at once; what stays is a record that the run took place — its dates, the credit it used, and what it cost to run — kept with your billing history.
- 05Delete
The uploaded files are deleted the moment the run ends, after the revision plan is prepared from them, whether the panel finished or failed. If a deletion fails, a scheduled sweep retries it until it succeeds.
- 06Confirm
If you need to show a sponsored-programs office that a specific document is gone, ask and we will confirm in writing when that run was submitted and when its files fell inside the deletion schedule.
The measures behind that lifecycle.
Every run is processed on its own, and every read and write is scoped to the account that owns it. One account's materials cannot be reached from another's run, and a run carries nothing from other accounts' runs.
TLS for all traffic to and from the service. Object storage and the database are encrypted at rest by our providers, who manage the keys.
Removing your files is automatic, not a person remembering to do it. It happens at the end of every run, finished or failed, and a scheduled sweep retries any deletion that fails, so nothing depends on the outcome or on anyone noticing.
Sign-in runs through our identity provider rather than a credential store we operate, with Google SSO available. GrantPanel never holds your password.
Bound by confidentiality and working to the handling rules on this page. The team is small, and every person with production access is named on request.
What we keep, and what we do not.
Where we actually stand on certification.
Stated plainly, including the gaps. A vendor page that claims everything is a vendor page you cannot use in a security review.
Everything a security review usually asks for.
If you are an IT security team or a research-development office evaluating GrantPanel for your investigators, start here rather than with a questionnaire.
Every third party that may process data, what it does, and where. Updated with 30 days' notice before any addition.
Read the list →Data Processing AgreementProcessor terms, security schedule, breach notification, and deletion commitments. Countersignable on request.
Read the DPA →Privacy PolicyWhat we retain, who processes it, and the choices available to the investigator whose work it is.
Read the policy →We complete standard vendor security questionnaires — CAIQ, HECVAT, and institutional equivalents — and will provide our data-flow summary and our technical and organisational measures schedule. There is no audit report to send; the table above says why. Write to hello@grantpanel.ai and expect a reply within two business days.
Found a vulnerability?
Report it to hello@grantpanel.ai. We acknowledge within one business day, keep you updated while we fix it, and will credit you publicly if you want the credit.
We will not pursue legal action against good-faith research that avoids privacy violations, service degradation, and access to data that is not your own. Please do not test with another researcher's proposal.