Trust & Security

How we handle your solicitation documents, what we do and do not do with them, and how human review works in every engagement.

Every output is reviewed by a human before delivery.

This is not a marketing claim — it is a structural part of how the service works. No output from the extraction pipeline reaches you without a human reviewing it first.

Extraction review

After the pipeline runs, the full extraction output is reviewed for missed requirements, incorrect type labels, and parsing errors. Errors are corrected before the checklist is assembled.

Compliance matrix review

The matrix mapping is verified against the extracted requirements. Proposal section assignments are checked for accuracy. No row ships without review.

Risk flag review

Risk flags are not auto-generated labels handed to you raw. Each flag is reviewed for context — whether it reflects a real gap, an ambiguous clause, or a compliance edge case — before the severity label is assigned.

Bid / no-bid review

The recommendation is written by a human based on the extracted evidence. It is not generated from a prompt and presented as analysis. It references specific requirements and flags from the document.


If we miss a mandatory requirement, we fix it at no cost.

If we miss a substantive mandatory requirement from the RFP package you provide, we will correct the deliverable at no additional charge.

What qualifies

A substantive mandatory requirement is an explicit shall, must, will, or required compliance instruction in the provided RFP package. This applies to documents received before delivery.

Scope of the guarantee

We fix the specific missed item at no cost. Amendments received after delivery require a separate update window. The guarantee does not cover proposal wins, scores, or agency compliance determinations — those remain with your team.


An NDA is available before any files are exchanged.

We offer a mutual non-disclosure agreement before any live solicitation documents are transferred. You do not need to send anything before the NDA is in place.

How to request

Email proposals@crestproof.com and ask for the NDA before intake. We will send it for review and signature before any file exchange begins.

Scope of the NDA

The NDA covers the solicitation documents you share and the engagement deliverables we produce. It applies before, during, and after the engagement. See NDA terms overview for the key provisions.


How we treat your solicitation documents.

Federal solicitations often contain pre-decisional information, past-performance references, or other sensitive content. We handle documents with that in mind.

Engagement scope only

We only use your materials to perform the requested proposal operations work. Your documents are not used to train public models, benchmark systems, or for any purpose outside the engagement.

No public exposure

Your documents are not uploaded to any public platform, shared with any third party, or indexed by any external service as part of our standard process.

Retention and deletion

Raw files are deleted after delivery or after an agreed retention window. You can request deletion at any time. We confirm deletion in writing on request. See full data handling policy.

Scope limits

We do not accept classified documents, CUI with handling restrictions we cannot meet, or ITAR-controlled materials at this stage. Civilian federal IT and services only.

Redacted samples with permission

If we ask to use your engagement as a redacted sample or case study, we will ask explicitly. We do not use past engagement deliverables as proof assets without your consent.


What CrestProof is and is not.

We are careful about how we describe this service. Here is the accurate picture.

Not autonomous

CrestProof does not submit proposals autonomously, make compliance decisions for you, or operate without human oversight. Every engagement involves active human review.

Not a guarantee

We do not guarantee bid wins, compliance pass/fail outcomes, or proposal scores. The tool improves process speed and organization. Outcomes depend on your team's proposal quality and the competitive environment.

Not applicable to all work

Our scope is civilian federal IT and services — GSA, HHS, VA, DHS, DOT, DOE, Treasury, USDA, and similar agencies. Defense-primary, classified, and ITAR-heavy work is outside our current scope.

Service-assisted, not self-serve SaaS

You do not log into a platform and run the tool yourself. We run the extraction, review the output, and deliver the package. This is intentional — it ensures quality before the deliverable reaches you.


Have a specific question about how we handle your documents?

Reach out before sending anything. We are happy to answer specific questions about document handling, scope limits, or the review process before you commit to a pilot.

Contact Us →