Security · Last updated 6 September 2026

Security facts, stated plainly.

This page describes controls visible in the current GrantConsole application and source. It does not claim a certification or independent audit that has not occurred, and it says what we do not yet have.

Authentication and sessions

  • Passwords are hashed with bcrypt before storage and never logged or emailed.
  • Repeated sign-in, sign-up and reset attempts are throttled per address.
  • Session cookies are signed, HTTP-only and SameSite=Lax; production cookies are marked Secure.
  • Password-reset and invitation links are single-use, expire (one hour and fourteen days), and are stored only as hashes.
  • Changing a password signs out every other device.

Organization boundaries and roles

  • Every record carries its organization, and the organization always comes from the authenticated session, never from the request.
  • Owner, manager, member and viewer capabilities are enforced by the server on every request; the interface only reflects them.
  • A record that belongs to another organization is indistinguishable from one that does not exist.
  • Changes are recorded in the activity history with who, what and when.

Uploads, transport and browser protections

  • Evidence uploads are limited to PDF, Word, Excel, CSV, PNG and JPEG, and the file contents are checked against the declared type before anything is stored.
  • Files are stored under generated keys in a per-organization folder outside the web root and served only through an authorised download.
  • All traffic is served over HTTPS (TLS) with HSTS, a strict Content-Security-Policy, and framing disabled.
  • State-changing requests require an origin check and a session-bound CSRF token.

Billing

Card details go directly to Stripe over their hosted checkout; GrantConsole never sees or stores card numbers. Stripe events that change a plan are verified by signature before they are applied.

Your data, your way out

  • Every grant, deliverable, task, budget line and report schedule exports to CSV at any time; every uploaded file can be downloaded.
  • An owner can delete the organization from Settings, which removes its records, uploads and invitations.
  • Support staff do not open customer workspaces without written permission.

Report a concern

Email support@grantconsole.com with “Security report” in the subject. Do not place sensitive records in the public demo or in an initial report.