Security & Trust

Financial controls should be explainable.

Prove It is built around server-side authorization, durable audit history, deterministic finance logic and human review. AI assists with extraction and explanation; it does not silently decide what is reimbursable.

Server-side access controlsPermanent audit eventsStripe-hosted payments
01Authenticate02Authorize03Validate04Review05Export06Audit

The product is designed so a finance user can see why an export is ready—or exactly why it is blocked.

Control model

Security and compliance controls built into the workflow.

We describe the controls that exist today and avoid claiming certifications or assurances that have not been independently obtained.

A

Server-side authorization

Organization membership and privileged actions are enforced on the server/database layer rather than relying only on what the browser displays.

R

Row-level access controls

Supabase-backed organization data uses access policies and server-side checks intended to keep one organization from reading or changing another organization’s financial workspace.

L

Durable audit history

Material export and review events are written to a permanent audit stream so generated, refused and reviewed actions can be reconstructed later.

$

Payments stay with Stripe

Paid plans use Stripe-hosted checkout. Prove It does not collect or store raw card numbers on its own site; Stripe handles the payment experience.

D

Deterministic finance logic

Math, reconciliations and configured compliance gates are rule-driven. Where a rule is unknown or unverified, the product is designed to ask for confirmation rather than invent an answer.

H

Human approval

Rule verification and authoritative financial outputs require human review. The system distinguishes sourced rules, review status and award-specific setup.

Responsible AI

AI helps with the repetitive work. It does not get final authority.

AI-assisted

Extraction

AI can help read payroll exports, documents and messy source files and map them into a structured workflow.

AI-assisted

Mapping & explanation

AI can suggest mappings and explain exceptions in plain language, while the product retains source context and requires review where needed.

Deterministic

Financial calculations

Totals, rate calculations, reconciliation and export gates should be reproducible. Those decisions are not delegated to a language model.

Unknown means unknown. If Prove It does not have a verified funder rule or award-specific requirement, the safe behavior is to show “confirm with funder” or block an authoritative export—not make up a requirement.
Data handling

Clear boundaries around operational data.

Organization separation

Customer financial data is organized by workspace/organization and governed by membership and permission checks.

Secrets stay server-side

Administrative database keys, Stripe secrets and webhook secrets are read from server environment variables and are not published as browser assets.

Internal operational files are not public

The Netlify build publishes a clean site artifact that excludes internal runbooks, SQL migrations, AI handoff notes, function source and development scripts.

What we do not claim

No invented trust badges.

Prove It does not claim SOC 2, FedRAMP, HIPAA, PCI certification, government endorsement or any other certification unless and until that status has actually been obtained and can be documented.

Stripe handles payment card collection through its hosted checkout. That does not mean every Prove It workflow is automatically covered by a Stripe certification. Buyers with formal security questionnaires or contractual requirements should contact us so requirements can be reviewed directly.

Buyer diligence

Questions we expect finance and IT teams to ask.

Can users from one organization read another organization’s data?

The application is designed around organization-scoped membership and database authorization. Cross-organization access is not an intended capability.

Can AI silently change a filed report?

No. Material financial changes and exports are governed by deterministic checks and audit history. Historical outputs are preserved rather than silently rewritten to a new rule version.

Does Prove It automatically file with a funder?

No. A person reviews outputs. The product prepares, validates and records the workflow; it does not represent that a funder submission occurred unless the user records that action.

Where are card numbers stored?

Payment checkout is hosted by Stripe. Prove It receives the customer/subscription identifiers necessary to provision and manage product access, not the raw card number.

What if my organization needs a formal security review?

Email ProveItFinancials@gmail.com with your questionnaire or required controls. Enterprise security requirements should be reviewed before contracting.

Need a security conversation before a pilot?

Send your organization’s security, privacy or procurement questions and we’ll address the controls that actually exist today.