Security & Trust Center

How we protect your grant proposals, documents, and account data. This page documents the controls our platform provides and the third-party services this app relies on — nothing more, nothing less.

Last updated: September 2026

Compliance

SOC 2 Type II

Inherited — Base44 platform

Independently audited. Full report available under NDA via the Base44 Security Trust Center.

ISO 27001

Inherited — Base44 platform

Information security management system certified at the platform level.

PCI DSS

Card processing — Stripe

Payment card data is handled by Stripe, a PCI DSS-compliant payment processor. We never store full card numbers.

These attestations are inherited from the Base44 platform and Stripe — My Grant CoPilot does not hold its own independent audit.

Security controls

Encryption

  • Data is encrypted in transit using TLS and at rest using AES-256.
  • Stored credentials are encrypted at rest via AWS Key Management Service (KMS).
  • Data is not end-to-end encrypted — platform administrators may access data when necessary for support and maintenance.

Authentication & Access

  • Sign-in is handled through OAuth 2.0 with email verification.
  • Sessions automatically expire after 8 hours of inactivity.
  • Row-level security (RLS) policies ensure users can only access their own records.

Infrastructure

  • Automatic HTTPS on all pages; the app is hosted on the Base44 managed cloud.
  • Public endpoints are rate-limited by default to blunt abuse.
  • The platform undergoes regular penetration testing and runs a security scan that checks data permissions, exposed secrets, and code vulnerabilities.

Application Hardening

  • Security headers (X-Frame-Options, Permissions-Policy) are configured to prevent embedding and restrict browser features.
  • Subscription and trial access is validated against tamper-proof server-side records, not client-writable profile fields.
  • Grant titles and user input are sanitized before use in email headers and notifications.

Data residency

App data is stored in the United States by default. EU or UK storage is available on the platform's Elite and Enterprise plans, which we have not elected. Residency controls where data is stored, not necessarily where it is processed; media files and billing information remain in the US.

Subprocessors

The services that process data on behalf of this app.

Base44
Hosting, database, authentication, email delivery, and AI orchestration
United States
Stripe
Payment processing and subscription billing
Global (PCI DSS)
Google
Calendar and Gmail connectors, plus Google Analytics traffic measurement
United States / Global
LinkedIn
LinkedIn connector for posting and profile access
Global
Anthropic, OpenAI & Google (AI models)
AI model providers reached through Base44 InvokeLLM — process prompts and generated content
United States

We do not share your data with any provider beyond those listed above.

Resources

Questions about security?

If you have a specific security or compliance question, our team will answer it directly.