What it can send, and what it cannot.
The most important security property of an autonomous agent is the list of things it is not allowed to do. That list is short, enforced in the product, and printed below rather than described as a philosophy.
The hard rules
Nothing outbound except your own submissions, on your own click.
The approval gate is architectural, not a preference. There is no setting that lets an automation submit on your behalf.
Your data
What we hold and why.
Your library — past performance, CPARS narratives, rates, certifications, documents you upload — plus the solicitations you track, the drafts you generate, and the record of what the agent did. We hold it because a draft written without it is not sendable.
Access
Who can see it.
Users you invite, at the permission level you set. Our staff access is limited to what is needed to operate and support the service, and support access to your content happens when you ask us to look at something.
AI processing
Where the model sits.
Reading and drafting use commercial large language models via their APIs. Content is sent for processing to produce your summaries and drafts. We do not use your content to train models, and we ask the same of our providers under their API terms.
If your prime or your agency imposes restrictions on which AI providers may touch proposal content, ask us before you buy and we will tell you exactly what is used.
Public data sources
What it reads from outside.
Federal solicitation notices, award records, entity and small-business directories, and wage determinations — all public sources. It does not scrape private portals or use your credentials to log in anywhere on your behalf.
What we do not claim
Certifications we have not earned are not listed here.
- No SOC 2 report today. If your procurement requires one, tell us and we will tell you where we are rather than sending a logo.
- No FedRAMP authorisation. This is commercial software for preparing your bids, not a system of record for government data.
- No CMMC assessment. Do not put controlled unclassified information into it on the assumption that it is an enclave for that purpose.
- No claim that your data never leaves our infrastructure — model processing means it does, and pretending otherwise would be the dishonest version of this page.
Security questions, questionnaires and specifics: security@govdealai.com. If a control matters to your bid, ask before you buy.
Trial it before your review finishes.
The trial cannot submit or export, which makes it a low-risk way to evaluate while procurement does its work.