Your Idea Is Safe With Us

Passwordless authentication. Server-validated JWTs. Encrypted at rest and in transit. No human reads your idea to score it.

Last updated: July 4, 2026 · View as Markdown

The short version: Your idea is encrypted, isolated, and processed only by AI. The only time a person is ever involved is a deck you hire the founder to build from your report, your call. Otherwise no human ever reads what you submit. We are a validation tool, not a competitor. You can delete your data anytime.

Vetting us first? Read whether Preuve AI is legit: who runs it, the reviews, and how to verify it yourself.

Passwordless

Magic-link / OTP only. No passwords to leak.

Encrypted

TLS 1.3 in transit, AES-256 at rest

SOC 2 Infrastructure

Supabase + Vercel, both SOC 2 Type II

You Control Your Data

Delete anytime from your account

Infrastructure Security

We build on enterprise-grade infrastructure from industry-leading providers:

  • Authentication: Supabase Auth (SOC 2 Type II) with passwordless magic-link / OTP sign-in only. We never set, store, hash, or transmit passwords because we never collect them. Session tokens are JWTs validated server-side on every authenticated API request.
  • Database: Supabase Postgres (SOC 2 Type II) hosted in the EU (eu-west-1, Ireland). Row-level security ensures users can only access their own data, enforced at the database level.
  • Hosting: Vercel (SOC 2 Type II). Edge network with automatic HTTPS, DDoS protection, and a CORS allowlist hardcoded to our production domains.
  • Payments: Stripe (PCI DSS Level 1) for new purchases. Legacy DodoPayments purchases remain on their original processor; records from our former processor Paddle are retained for accounting only. We never see or store card details.
  • AI Providers: Your idea is processed through enterprise APIs from Google (Gemini), Anthropic (Claude), OpenAI (GPT), and xAI (Grok). These providers do not use your data to train their models under their enterprise API terms. Requests may be routed through managed model platforms and gateways such as Amazon Bedrock and OpenRouter, each with its own data handling policies.
  • Market Research: Market and competitive research uses third-party data providers. They never receive your idea or any personal data, only broad market and category terms.
  • Abuse Defenses: Server-side rate limiting on every public endpoint, with stricter limits on authentication endpoints. IP-based abuse detection auto-blocks after repeated alerts and is IPv6-aware to prevent rotation evasion. Disposable-email signups are blocked at the source.
  • Input & Output: Prompt-injection detection and input sanitization run on every report submission. Server-side paywall enforcement strips locked sections from API responses; locked content never leaves our server. Audit log wraps every API handler.

Who Sees Your Idea?

Zero humans. Your idea never crosses a human inbox, dashboard, or screen. AI researches it, generates your report, that is it. The one exception is yours to choose: buy the $499 Investor Package and you are hiring the founder to personally build your pitch deck and memo from your report. Outside that, nothing you submit is ever seen by a person.

Your idea is:

  • Never shared with other users or sold to anyone
  • Processed by AI providers (Google, Anthropic, OpenAI, xAI) strictly to generate your report. These providers do not train on your data under their enterprise API terms
  • May be routed through managed model platforms and gateways such as Amazon Bedrock and OpenRouter, each with its own data handling policies
  • Stored encrypted in your private account
  • Aggregate statistics (score distributions, risk rates) may appear in public research reports. Never individual ideas, names, or identifying details

Bottom line: your idea is yours. You can delete it, and everything tied to it, in one click, whenever you want.

Data Encryption

  • In transit: All data encrypted with TLS 1.3 (256-bit)
  • At rest: Database encrypted with AES-256
  • Isolation: Row-level security. Your data is logically separated from other users
  • No plaintext secrets: Sensitive data is never stored unencrypted

Your Control

You own your data. You can:

  • View: Access all your reports in your account
  • Delete: Remove individual reports or your entire account
  • Export: Download your analysis data

When you delete data, it is permanently removed from our systems.

Common Questions

Will you steal my idea?

No. We have analyzed 6,000+ ideas to date, from weekend projects to VC-backed startups. If we stole ideas, we would have been exposed by now. We are a validation tool, not a venture studio.

Your idea is private. I am a solo founder who can barely keep up with his own product. I definitely do not have time to steal yours.

- Vincent, Founder

Can your employees see my idea?

No. Preuve is a solo company with no employees, and your idea is processed entirely by AI to research and score it. The one exception is opt-in: buy the $499 Investor Package and you are hiring the founder to build your deck and memo from your report. Access to production data requires multi-factor authentication and is logged for security audits.

Is my idea used to train AI?

Our AI providers (Google, Anthropic, OpenAI, xAI) operate under enterprise API terms that prohibit using your data for model training. Requests may be routed through managed model platforms and gateways such as Amazon Bedrock and OpenRouter, each with its own data handling policies.

How is my data protected if something goes wrong?

Supabase and Vercel both run formal incident response programs. Per GDPR Article 33, we notify affected users within 72 hours of confirming a breach that affects their data. Our delete-account endpoint immediately purges your data from Postgres and the auth tables on request, and refund-related data revocation is handled the same way.

Why no password?

Passwords are the most-attacked surface in any web app. By using one-time codes and magic links instead, we remove credential stuffing, password-reuse exposure, brute force, and password-leak risk in one move. You sign in by clicking a link we email you. That is the entire mechanism.

Found a vulnerability?

We take security reports seriously. If you have found a vulnerability in Preuve, email security@preuve.ai.

  • We respond within 24 hours on weekdays.
  • Please do not publicly disclose the issue until we have had a reasonable chance to fix it.
  • Avoid actions that would degrade service for other users (no DoS, no scraping, no testing on accounts that are not yours).
  • No bounty program yet, but we publicly credit responsible reporters once a fix is shipped, if you want the credit.

Questions about security? Contact us at hello@preuve.ai