Security & Trust

    Built for the data standards your clients expect

    Consultants working with governments, multilaterals, and enterprise clients can't compromise on data protection. Here is exactly how we protect your work.

    Encryption in transit & at rest

    All traffic is served over TLS 1.2+. Documents, client records, and account data are encrypted at rest using AES-256 on managed infrastructure (Supabase / AWS).

    Isolated, row-level secured data

    Every table that holds customer content is protected by row-level security. You can only ever read or write data that belongs to your account — enforced at the database layer, not just in the app.

    Your work is never used to train AI

    We use enterprise AI gateways (OpenAI and Google via Lovable AI Gateway) under terms that prohibit training on customer inputs or outputs. Your proposals, contracts, and client data are never used to improve a third-party model.

    You own your content

    Everything you create in ConsultSuite Pro — documents, contracts, client records, branded exports — belongs to you. You can export it at any time, and we will delete it on request.

    Our AI training stance

    ConsultSuite Pro uses large language models from OpenAI and Google, accessed through enterprise gateways under data processing terms that prohibit using customer inputs or outputs to train, fine-tune, or improve any third-party model.

    We do not train models on your content. We do not sell, share, or license your content to model providers, data brokers, or any third party for AI training purposes. Your client briefs, proposals, contracts, and reports stay yours.

    Operational metadata (request timestamps, model used, token counts) is logged for abuse prevention, billing, and reliability — never the content of your prompts beyond a short retention window.

    Data retention

    Active account data
    Retained for the life of your account.
    Deleted documents
    Soft-deleted for 30 days, then permanently purged.
    Closed accounts
    All customer content deleted within 30 days of account closure.
    Backups
    Encrypted backups rotated on a 30-day cycle.
    AI prompt logs
    Operational logs retained up to 30 days for abuse prevention, then deleted. Never used for training.
    Billing records
    Retained as required by tax and accounting law (typically 7 years).

    You own your content

    You retain full intellectual property rights to every document, contract, client record, and deliverable you create or upload to ConsultSuite Pro. We act as a processor of that data on your behalf, not an owner of it.

    • Export your documents at any time as DOCX, PDF, or PPTX with your branding intact.
    • Request a full data export of your account in a machine-readable format.
    • Delete individual documents or your entire account — purges complete within 30 days.
    • We will never use your content as marketing material, sample data, or training input without explicit written consent.

    Compliance & controls

    SOC 2 Type II

    In progress

    GDPR-aligned

    Data subject rights supported

    EU & US hosting

    Managed cloud regions

    SSO & MFA

    On Professional and above

    Some certifications are in progress as we mature. We publish status changes on this page and in our changelog. For procurement reviews, security questionnaires, or DPAs, contact us below.

    Reporting a security issue

    If you believe you've found a security vulnerability, please report it responsibly to security@consultsuitepro.com. We acknowledge reports within two business days and will keep you updated through resolution.

    Please do not publicly disclose issues before we've had a chance to investigate and remediate.

    Security FAQ

    Quick answers to the questions we hear most often from procurement and InfoSec teams.

    Need a DPA or security questionnaire?

    We support procurement and InfoSec reviews for firms working with regulated clients.