What a government buyer should know before trusting us with applicant data.
GrantDesk handles applicant records, financial narratives, and award histories for public agencies. This page states plainly how that data is protected, exactly where AI sits in the workflow, who owns the data, and what your security and procurement reviewers can request from us. If your review needs something that is not here, ask and we will provide it or tell you honestly that we cannot.
Security overview
GrantDesk is designed to the standard a public-agency security review expects of a system that touches applicant PII and public money:
- Encryption in transit and at rest. Data moving between applicants, staff, and the platform is encrypted in transit, and stored data is encrypted at rest.
- Role-based access control. Staff, reviewers, and administrators see only what their role requires. Reviewer assignments and conflict-of-interest rules are enforced by the system, not by convention.
- Audit logging. Eligibility decisions, scores, award actions, and record edits are logged with who acted and when, so any determination can be traced for a monitor or auditor.
- Data minimization for applicant PII. Intake forms are designed to collect only the fields a program actually requires, and sensitive applicant fields are restricted to the roles that need them.
We do not currently hold third-party certifications, and we do not claim any. What we offer instead is transparency: our vendor security assessment materials describe the actual architecture and controls, and we answer your InfoSec questionnaire directly.
Where AI sits, and where it never goes
AI in GrantDesk does three jobs: it checks submissions for completeness against the program's required-item list, it prepares draft summaries and scoring sheets for reviewers, and it watches compliance and reporting deadlines across active awards. Every AI output is labeled as such and is reviewed by staff before it counts.
The boundary is hard, and it is worth stating without qualification:
- AI never makes or changes an award decision. Eligibility determinations, scores, and awards belong to your staff and reviewers.
- AI never edits a record without a log entry.
- Applicant data is never used to train models, ours or anyone else's.
Data ownership and export
The agency owns its data. All of it, at all times. That means:
- Full export on demand. Applications, attachments, scores, award records, and audit history can be exported in standard formats (CSV, JSON, and original attachment files) whenever you ask, without a support ticket negotiation.
- Defined disposal at contract end. When an engagement ends, you receive a complete export, and we delete your data from our systems on a defined schedule that is written into the agreement, with confirmation when it is done.
- No hostage terms. Leaving GrantDesk never costs you your records. Retention of public records remains governed by your own retention rules, and the export exists so you can meet them in your own systems.
Reliability
A grants system has one unforgivable failure mode: losing an application. GrantDesk is designed so that cannot happen silently. Every submission is acknowledged to the applicant and tracked to a disposition, so nothing sits in an untracked state. Intake and processing pipelines are monitored with alerting, so a failure is a ticket for us to fix, never a quiet gap your office discovers at the end of a cycle.
Vendor packet
Procurement and InfoSec reviews should not have to chase a vendor for paperwork. The following are prepared and available on request:
- Vendor security assessment materials
- W-9
- Certificates of insurance
- References
If your agency uses its own questionnaire or risk-evaluation form, send it over and we complete it.
About the company
GrantDesk is offered by JS Technology Solutions, Inc., an Illinois-registered technology firm that designs and operates secure workflow and compliance software for public-sector and education clients. Company site: www.jstech-inc.com. Contact: hello@getgrantdesk.com.