Skip to main content
Back to Proven

Legal

Security

Last updated: June 24, 2026

Infrastructure

Proven runs on Vercel with automatic TLS. The database and backend run on Convex, with encryption in transit (TLS 1.3) and at rest.

Authentication

Handled by Convex Auth. Passwords are never stored in plaintext. Session tokens are short-lived.

Payments

All payments go through Stripe at PCI DSS Level 1. Card numbers never reach Proven's systems. Webhook signatures are verified on every event.

Application Security

  • All inputs validated server-side
  • Your reports, idea submissions, and Sharpen corrections are scoped to your account only
  • CORS and CSP headers on all endpoints
  • Webhook payloads verified with signing secrets before processing

Validation Data Isolation

Your submitted ideas and generated reports are private. No other user can read your validation data. Admin access covers account metadata only (email, brief balance, karma score).

The one exception: some plans include a human-reviewed brief. When you explicitly request it, a member of the Proven team reads that specific brief to provide feedback. This access is scoped to that single brief, only triggered by your request, and fully disclosed in the Privacy Policy.

Vulnerability Reporting

Found something? Email dcanelprofessional@gmail.com. We'll respond within 48 hours.