Authentication and sessions
- Passwords are hashed with bcrypt before storage and never logged or emailed.
- Repeated sign-in, sign-up and reset attempts are throttled per address.
- Session cookies are signed, HTTP-only and SameSite=Lax; production cookies are marked Secure.
- Password-reset and invitation links are single-use, expire (one hour and fourteen days), and are stored only as hashes.
- Changing a password signs out every other device.
Organization boundaries and roles
- Every record carries its organization, and the organization always comes from the authenticated session, never from the request.
- Owner, manager, member and viewer capabilities are enforced by the server on every request; the interface only reflects them.
- A record that belongs to another organization is indistinguishable from one that does not exist.
- Changes are recorded in the activity history with who, what and when.
Uploads, transport and browser protections
- Evidence uploads are limited to PDF, Word, Excel, CSV, PNG and JPEG, and the file contents are checked against the declared type before anything is stored.
- Files are stored under generated keys in a per-organization folder outside the web root and served only through an authorised download.
- All traffic is served over HTTPS (TLS) with HSTS, a strict Content-Security-Policy, and framing disabled.
- State-changing requests require an origin check and a session-bound CSRF token.
Billing
Card details go directly to Stripe over their hosted checkout; GrantConsole never sees or stores card numbers. Stripe events that change a plan are verified by signature before they are applied.
Your data, your way out
- Every grant, deliverable, task, budget line and report schedule exports to CSV at any time; every uploaded file can be downloaded.
- An owner can delete the organization from Settings, which removes its records, uploads and invitations.
- Support staff do not open customer workspaces without written permission.
Report a concern
Email support@grantconsole.com with “Security report” in the subject. Do not place sensitive records in the public demo or in an initial report.
