Security & Trust
Consultants working with governments, multilaterals, and enterprise clients can't compromise on data protection. Here is exactly how we protect your work.
All traffic is served over TLS 1.2+. Documents, client records, and account data are encrypted at rest using AES-256 on managed infrastructure (Supabase / AWS).
Every table that holds customer content is protected by row-level security. You can only ever read or write data that belongs to your account — enforced at the database layer, not just in the app.
We use enterprise AI gateways (OpenAI and Google via Lovable AI Gateway) under terms that prohibit training on customer inputs or outputs. Your proposals, contracts, and client data are never used to improve a third-party model.
Everything you create in ConsultSuite Pro — documents, contracts, client records, branded exports — belongs to you. You can export it at any time, and we will delete it on request.
ConsultSuite Pro uses large language models from OpenAI and Google, accessed through enterprise gateways under data processing terms that prohibit using customer inputs or outputs to train, fine-tune, or improve any third-party model.
We do not train models on your content. We do not sell, share, or license your content to model providers, data brokers, or any third party for AI training purposes. Your client briefs, proposals, contracts, and reports stay yours.
Operational metadata (request timestamps, model used, token counts) is logged for abuse prevention, billing, and reliability — never the content of your prompts beyond a short retention window.
You retain full intellectual property rights to every document, contract, client record, and deliverable you create or upload to ConsultSuite Pro. We act as a processor of that data on your behalf, not an owner of it.
In progress
Data subject rights supported
Managed cloud regions
On Professional and above
Some certifications are in progress as we mature. We publish status changes on this page and in our changelog. For procurement reviews, security questionnaires, or DPAs, contact us below.
If you believe you've found a security vulnerability, please report it responsibly to security@consultsuitepro.com. We acknowledge reports within two business days and will keep you updated through resolution.
Please do not publicly disclose issues before we've had a chance to investigate and remediate.
Quick answers to the questions we hear most often from procurement and InfoSec teams.