Server-side authorization
Organization membership and privileged actions are enforced on the server/database layer rather than relying only on what the browser displays.
Prove It is built around server-side authorization, durable audit history, deterministic finance logic and human review. AI assists with extraction and explanation; it does not silently decide what is reimbursable.
The product is designed so a finance user can see why an export is ready—or exactly why it is blocked.
We describe the controls that exist today and avoid claiming certifications or assurances that have not been independently obtained.
Organization membership and privileged actions are enforced on the server/database layer rather than relying only on what the browser displays.
Supabase-backed organization data uses access policies and server-side checks intended to keep one organization from reading or changing another organization’s financial workspace.
Material export and review events are written to a permanent audit stream so generated, refused and reviewed actions can be reconstructed later.
Paid plans use Stripe-hosted checkout. Prove It does not collect or store raw card numbers on its own site; Stripe handles the payment experience.
Math, reconciliations and configured compliance gates are rule-driven. Where a rule is unknown or unverified, the product is designed to ask for confirmation rather than invent an answer.
Rule verification and authoritative financial outputs require human review. The system distinguishes sourced rules, review status and award-specific setup.
AI can help read payroll exports, documents and messy source files and map them into a structured workflow.
AI can suggest mappings and explain exceptions in plain language, while the product retains source context and requires review where needed.
Totals, rate calculations, reconciliation and export gates should be reproducible. Those decisions are not delegated to a language model.
Customer financial data is organized by workspace/organization and governed by membership and permission checks.
Administrative database keys, Stripe secrets and webhook secrets are read from server environment variables and are not published as browser assets.
The Netlify build publishes a clean site artifact that excludes internal runbooks, SQL migrations, AI handoff notes, function source and development scripts.
Prove It does not claim SOC 2, FedRAMP, HIPAA, PCI certification, government endorsement or any other certification unless and until that status has actually been obtained and can be documented.
Stripe handles payment card collection through its hosted checkout. That does not mean every Prove It workflow is automatically covered by a Stripe certification. Buyers with formal security questionnaires or contractual requirements should contact us so requirements can be reviewed directly.
The application is designed around organization-scoped membership and database authorization. Cross-organization access is not an intended capability.
No. Material financial changes and exports are governed by deterministic checks and audit history. Historical outputs are preserved rather than silently rewritten to a new rule version.
No. A person reviews outputs. The product prepares, validates and records the workflow; it does not represent that a funder submission occurred unless the user records that action.
Payment checkout is hosted by Stripe. Prove It receives the customer/subscription identifiers necessary to provision and manage product access, not the raw card number.
Email ProveItFinancials@gmail.com with your questionnaire or required controls. Enterprise security requirements should be reviewed before contracting.
Send your organization’s security, privacy or procurement questions and we’ll address the controls that actually exist today.