Clear boundaries for working files, AI, and Human Review.

AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Project files and accepted review sources stay separate.

Upload alone starts no AI or Human Review. Use an official identifier or URL or, when offered, an exact manual snapshot.

Read Trust Center

Source-backed outputs

Citations and excerpts stay close to important answers.

Exact accepted-source boundary

Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

SourceFlag Human Verified

Human Verified applies only to the reviewed brief, workbook, and governed workspace.

Workspace access

Authorized SourceFlag Team access is limited to the accepted official package or manual snapshot and the review records needed for the service.

Self-serve scope

Create projects with authorized public or unclassified files without starting AI, Human Verified review, or a service clock. Turn on unverified AI outputs only when you choose, or request Human Review with an official identifier or URL or, when offered, an exact authorized manual-review snapshot.

Project files and accepted Human Review sources

AI features and Human Review may be used only with customer-authorized public or unclassified solicitation material. A request begins only after the SourceFlag Team accepts the named source and confirms payment, an available review, capacity, and schedule.

private_storage_only boundary

Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project. Do not upload CUI, FCI, classified, ITAR- or EAR-controlled material, credentials, regulated personal data, procurement-sensitive material, or non-public government-controlled data in any mode.

Source-backed outputs

Ask answers and review outputs are designed to stay tied to source files, citations, excerpts, pages, and attachment references.

SourceFlag Human Verified

SourceFlag Human Verified means the SourceFlag Team reviewed the published RFP brief, compliance workbook, and governed workspace against the accepted official solicitation source. The review method is AI-assisted preparation, source checks, and SourceFlag Team review.

Workspace access controls

Workspaces are intended to separate access by account, membership, invitation, and role flow.

AI processing posture

SourceFlag uses its disclosed AI provider only when a customer turns on an AI feature for eligible public or unclassified material.

Data export and deletion

Workspace data can be exported or deleted after a validated authorized request, subject to the applicable contract and documented exceptions.

What SourceFlag is not

No unsupported compliance or security promises.

The trust posture is intentionally conservative. SourceFlag supports review; it does not become the authority on agency interpretation, compliance, or proposal risk.

No SOC 2 report is currently offered.
No FedRAMP authorization is currently offered.
No CMMC certification is currently offered.
Not a CUI, Federal Contract Information (FCI), ITAR, classified, or export-controlled hosting environment.
Not legal, procurement, pricing, capture, compliance, security, or export-control advice.
Not a guarantee that every requirement, deadline, risk, ambiguity, amendment, or instruction will be found.
Human Verified does not mean guaranteed compliance, guaranteed package completeness, or a guaranteed procurement result.

Security practices

SourceFlag uses commercially reasonable administrative, technical, and organizational safeguards designed to protect information. No transmission, storage, or processing method is perfectly secure.

Upload only files you are authorized to use. Do not upload executable files, credentials, malware, or prohibited government-controlled data. Workspace administrators remain responsible for access, permissions, file authority, and review of AI-generated outputs.

The reviewed brief, compliance workbook, and governed workspace remain distinct from later editable work. Customer or AI changes do not inherit Human Verified status, and an editable project carries no persistent verified badge. Ordinary business-confidential proposal material may be stored and manually organized only in a private_storage_only project. AI features, Human Review, and background processing are locked off for that project.

Subprocessors and service providers

The current Privacy Policy names these providers for AI processing, authentication, database/storage, hosting, background jobs, billing, business email, and optional walkthrough video embeds:

OpenAI APISupabaseStripeVercelRenderGoogle WorkspaceResendYouTube privacy-enhanced embeds
View subprocessors and service providers

Trust and security questions, answered.

The answers stay aligned with the public-source, private_storage_only, prohibited-content, Privacy Policy, and Terms boundaries.

Need to report a privacy or security concern?

Use the published Privacy contact for privacy requests, security concerns, and data-handling questions.

Contact privacy@sourceflagworkspace.com