The Security page
Updated August 14, 2026
Security is the sixth item in the sidebar. Its subhead states the point plainly: "How ProClose treats your book of business." The page holds six commitment cards, in order.
#Deterministic by default
Badge: Built in.
Proposals are parsed and assembled by a rules engine, not a language model. Your documents never leave the workspace, nothing is used for training, and there are no per-proposal AI costs.
The card also describes an optional Claude assistant, reading the vault to suggest and apply changes in plain English. In the current release, the assistant thread you can open from the outline editor answers a small set of scripted commands rather than holding a live conversation. See The proposal assistant for exactly what works today.
Preview notePreview note: the deterministic parsing and the "documents never leave the workspace" commitment are live now. The full conversational assistant described on this card is not yet wired in.
#Carrier masking on every artifact
Badge: Built in.
Client-facing slides, PDFs, and exports show "A-rated company" instead of the carrier name, by rule. Your markets stay yours, even when a proposal gets forwarded around. This is a real, functioning rule, not a display preference you can turn off. See Carrier masking for where the real carrier name still shows to you, and where it never shows to a client.
#Fees can never be forgotten
Badge: Built in.
Policy fees and agency fees are stamped by code and validated before a proposal can finish. The audit trail shows they were disclosed, which is exactly what you want in an E&O file. Fee stamping is covered end to end in Premium and agency fees and The fee schedule.
#Roles and a full audit trail
Badge: Built in.
Owner and producer roles. Every build, edit, export, and email is logged per proposal, so you always know what the client was shown and when. The role split (who sees the whole book, who edits the Vault) is covered in Signing in and user roles. The audit trail itself lives on the Dashboard's Recent activity card and, per proposal, in an Activity on this proposal section, both drawing from the same log.
Preview notePreview note: two different things sit behind that log today. Creating, updating, or deleting a proposal, and updating or restoring the Vault, updating the Brand page, or changing call recording retention, each write a permanent, timestamped, per-user record to your workspace's own database. That record survives a reload, is never lost, and ships in a full workspace export (see Export your workspace, below). What you actually look at, the Recent activity card and the Activity on this proposal panel, is different: a live view of your current session that covers more ground (it also logs things like signing in, opening the outline editor, and every export or print) but starts over empty each time you sign back in, rather than re-reading the durable log. The safety-relevant record is never lost either way; the on-screen feed is a session-scoped convenience view of a wider list.
#Encryption
Badge: Built in.
TLS in transit on every request. Your quotes, policies, and loss runs are parsed entirely in your browser with pdf.js and never uploaded to a server at all, so there is no document store to isolate or breach in the first place. A workspace that connects its own RingCentral app gets that client secret and JWT encrypted at rest with AES-256, and call transcripts and nightly database backups carry the same protection when an encryption key is configured on the server. The live database file on disk is not separately encrypted beyond that.
Underneath the card, a live status line reports what is actually true on your server right now: whether local backups are running (and the result of the last one), whether an off-box backup copy is configured, and whether call transcripts on file are currently encrypted. That line is a real check, not a fixed promise.
#SOC 2 Type II
Badge: Roadmap.
Controls are being built against SOC 2 from day one, with the audit window planned for the first production year. That audit is the roadmap item. Retention windows, a full workspace export, and workspace deletion are not waiting on it, they are live today, right on this page. See Workspace controls on this page, below. SAML SSO is the one piece not built yet.
The Roadmap badge on this card now refers specifically to the SOC 2 audit itself and to SAML SSO, not to the export, retention, and delete controls it used to bundle in with them.
#What the badges mean
Every card on the page carries one of two badges today, and they are worth reading literally:
| Badge | What it means |
|---|---|
| Built in | Working in the app you are using right now. |
| Roadmap | A stated direction and commitment, not a feature or certification in place today. |
Five of the six commitment cards read Built in. Only SOC 2 Type II reads Roadmap, and even that card is now honest that most of what it used to defer to later, retention, export, and delete, already shipped; only the audit itself and SAML SSO remain a stated direction rather than a fact today.
#Workspace controls on this page
Below the six commitment cards, the Security page also holds three real, working controls. All three are owner-only: a producer does not see them at all, rather than seeing them disabled.
Export your workspace
Download a copy of everything downloads one JSON file holding everything in your workspace: the current Vault plus its complete version history, every proposal with its full content, the full audit trail, and the user list. A password hash or a stored RingCentral credential can never end up in this file, they are left out of what gets collected, not merely hidden from the download.
Call recording retention
Set a number of days, from 1 to 3650, and call recordings and transcripts older than that are purged automatically. Leave the field blank, or enter 0, to keep them indefinitely, which is also what a workspace that has never touched this setting already does. This only governs call data. It has no effect on the Vault, proposals, or anything else in the workspace.
Delete this workspace
Permanently deletes every proposal, the Vault and its entire version history, the audit trail, and every user in the workspace. When the workspace connected its own RingCentral app rather than relying on the server's shared credentials, its call recordings, audio, and cached transcripts are erased from the server's disk too; when it shares the server's own RingCentral credentials, that call data lives alongside other workspaces' and is left in place, and the page tells you plainly which case yours is in before you confirm.
Confirming requires typing the workspace's own slug exactly. There is no other confirmation step and no undo. Two workspaces can never be deleted through this control no matter who asks: the public demo workspace, and whichever workspace is the only one left on the server. Download an export first if there is any chance you will want this later.