Trust

Subprocessors

Last updated: 17 July 2026

To run ProposalBolt we rely on a small set of trusted infrastructure providers ("subprocessors"). Each processes only the data it needs to perform its function, under its own security program and data-processing terms. This is the current list; we'll update this page before adding a new subprocessor that handles customer data.

Subprocessor Purpose Data processed Primary hosting
Supabase (on AWS)Database, authentication, file storageAccount, workspace, proposal, signature and payment-record data; uploaded filesAWS (region configured for the project)
VercelApplication hosting, CDN and serverless functionsHTTP request metadata; content in transitGlobal edge network
RazorpayPayment collection, subscriptions and payoutsPayment and payout details, transaction recordsIndia
ResendTransactional & notification emailRecipient email address and message contentUnited States / EU
Google (Gemini API)AI proposal drafting and editingThe prompt text and document context you submit for generationGoogle Cloud

How your data is protected across these providers

Data is encrypted in transit (TLS) to and from every subprocessor, and at rest within our database provider. Access to production systems is limited and authenticated. Each subprocessor is engaged under its own data-processing agreement.

AI and your content

When you use AI features, the text you choose to generate or edit is sent to the AI provider to produce a response. We do not sell your data, and we do not use your client documents to train models.

Changes & notice

We will post material changes to this list here. Enterprise customers can request advance email notice of new subprocessors as part of their agreement — contact us to arrange it.

Questions about this list or our data practices? Email our team. See also our Data Processing Addendum, Security overview and Privacy Policy.

ProposalBolt