Trust Center

    Your data is protected at every step

    RFI Know helps organizations complete security questionnaires, RFIs, RFPs, and vendor assessments faster — so we understand that the documents you upload may contain sensitive business information. We designed the platform with security as a core principle.

    Trust at a glance

    We use modern managed infrastructure, encryption, access controls, and audit logging to protect customer data.

    Encryption in Transit

    TLS 1.2+ protects all communication between your browser and RFI Know.

    Encryption at Rest

    Customer data is encrypted at rest (AES-256) by our managed cloud infrastructure providers.

    Tenant Isolation

    Each organization's data is logically separated from every other customer.

    Access Controls

    Only authenticated users within your organization can access your questionnaires and documents.

    Audit Logging

    Important actions are recorded for accountability and troubleshooting.

    Secure Password Storage

    Passwords are hashed using bcrypt and are never stored in plain text.

    Security controls

    How customer data is protected across the platform.

    Data protection

    • All traffic encrypted with HTTPS/TLS, with HTTP Strict Transport Security (HSTS) enforced
    • Data encrypted at rest (AES-256) by Neon (database) and Cloudflare R2 (file storage)
    • Uploaded questionnaires, responses, generated answers, comments, and attachments remain private to your organization

    Organization isolation

    • Each company has its own isolated workspace
    • Users can only access data belonging to organizations they have been invited to
    • Isolation enforced in the application on every query, with database row-level security policies as defense in depth

    Access & authentication

    • Email and password authentication with mandatory email verification
    • Passwords hashed with bcrypt — never stored in plain text
    • Server-side sessions with secure, HTTP-only cookies
    • Accounts temporarily locked after repeated failed login attempts; login endpoints rate-limited
    • Role-based permissions (owner, admin, member) — only owners manage billing; only owners and admins manage the knowledge base or invite teammates

    Monitoring & continuity

    • Security-relevant events and administrative actions recorded in an audit log — logins, failed attempts, data exports, questionnaire and team changes
    • Platform health monitored with operational logging
    • Daily database snapshots and point-in-time recovery with a 14-day window

    Infrastructure

    We partner with industry-leading infrastructure providers rather than operating our own servers — benefiting from enterprise-grade physical security, redundancy, monitoring, and availability.

    Railway
    Application hosting
    Neon
    PostgreSQL database
    Cloudflare
    Content delivery & DNS
    Cloudflare R2
    Encrypted file storage
    SendGrid
    Email delivery
    Stripe
    Payment processing
    OpenAI
    AI answer generation

    AI & customer data

    AI features exist for one purpose: helping you answer your questionnaires. We use OpenAI's API for answer generation and semantic search.

    • Your uploaded documents and past answers are used solely to generate responses within your own organization.
    • Customer data is never shared with other RFI Know customers.
    • We do not use one customer's documents to answer questions for another customer.
    • Customer content is not used to train AI models. OpenAI does not train on API inputs or outputs by default unless the customer opts in — and we have not opted in.
    • AI-generated answers cite the specific documents and past answers they were based on, and a relevance gate filters out weak matches — so you can verify every suggestion against its sources.

    Your data, under your control

    What happens to your content — from upload to deletion.

    When you upload documents

    • Documents are stored securely in encrypted cloud storage.
    • Text is extracted and processed to enable semantic search over your own content.
    • AI suggestions are generated only for your organization.
    • Documents remain under your control.
    • You may delete uploaded documents at any time.

    Team collaboration

    Organizations can:

    • Invite teammates with role-based permissions
    • Assign questions to team members
    • Leave comments
    • Upload supporting evidence and attachments

    Deletion & retention

    • Questionnaires and documents can be deleted from within the platform at any time.
    • Organization owners can delete their account entirely.
    • Upon account termination, customer data is removed according to our retention policy.

    See our Terms of Service and Privacy Policy.

    Compliance

    RFI Know follows industry security best practices while continuing to expand our compliance program.

    Secure software development with automated security testing
    Encryption in transit and at rest
    Access controls and least privilege
    Audit logging
    Infrastructure security through managed providers
    Regular dependency updates
    SOC 2 is on our product roadmap as we continue to grow.

    Responsible Disclosure

    Found a security issue? We appreciate responsible disclosure and will investigate all legitimate reports promptly.

    [email protected]

    Frequently asked questions

    Where is customer data stored?+

    Customer data is stored in the United States on managed cloud infrastructure: our database is hosted by Neon (PostgreSQL) and uploaded files are stored in Cloudflare R2. Both providers encrypt data at rest.

    Can other customers access my information?+

    No. Each organization's data is isolated. Every query is scoped to your organization, and AI features only ever retrieve content belonging to your own workspace.

    Do you use my data to train AI?+

    No. We use OpenAI's API to generate answers, and OpenAI does not train its models on API inputs or outputs by default unless the customer opts in — and we have not opted in. Your content is used solely to generate responses for your own organization.

    Can I export my questionnaires?+

    Yes. Completed questionnaires can be exported back into their original Excel format (preserving the original layout), as CSV, or as a ZIP bundle that includes attachments.

    Can I delete my data?+

    Yes. You can delete individual documents and questionnaires from within the platform at any time, and organization owners can delete the account entirely. After account termination, remaining data is removed according to our retention policy (see our Terms of Service).