Trust & security

Security built for GovCon

Government contractors care deeply about security. ProposalMatrix is designed with enterprise-grade controls, encryption, and auditability — so you can focus on winning proposals.

Infrastructure

AWS-hosted with VPC-isolated database and CloudFront CDN. No public database exposure.

Encryption

TLS in transit, AES-256 at rest. S3 SSE-KMS and Aurora encryption for all data.

Authentication

Amazon Cognito with MFA support. Secure session management and token handling.

Authorization

Role-based access control (RBAC) with 6 granular roles. Least-privilege by default.

Data isolation

Multi-tenant architecture with row-level workspace isolation. Your data stays yours.

AI safety

Bedrock Guardrails for PII detection and redaction. No training on customer data.

Audit trail

Every operation logged with userId, action, resource, and timestamp. Full traceability.

Kill switch

Workspace administrators can disable all AI generation instantly when needed.

Backup & recovery

Aurora automated backups with 35-day retention. S3 versioning for documents.

Compliance posture

ProposalMatrix is designed to support SOC 2 alignment. Our architecture, access controls, encryption, and audit logging are built with compliance in mind. We are not yet SOC 2 certified — certification is planned for a future phase. For questions about our compliance roadmap, contact us.

Frequently asked questions