Frequently Asked Questions
Every answer says what the platform actually does today. Compliance answers follow the pass-through model: GovConHouse computes, you review, sign, and submit. Final compliance wording stands for legal review.
Compliance and security
Section titled “Compliance and security”Does GovConHouse submit my SPRS score or CMMC affirmation to the government?
No. The platform computes scores, tracks controls, and exports documents. You review and submit them through PIEE with your own credentials. The in-app submit route returns an honest “live SPRS submission is disabled” because the platform does not transmit to PIEE. See the SPRS scoring doc.
Is GovConHouse FedRAMP authorized, SOC 2, or ISO 27001 certified?
No. GovConHouse holds no FedRAMP authorization, SOC 2, ISO 27001, or CMMC certification for the platform itself. The platform’s outputs are material for your own assessments, not certifications anyone holds on your behalf. See the compliance center.
How is my data encrypted?
Uploaded evidence files are encrypted at rest with Fernet when the operator
sets FERNET_KEY. CUI-marked contract fields are encrypted at the application
layer when CUI_ENCRYPTION_KEY is set. Both keys are free and open source.
When a key is not set, the platform stores plaintext and logs that state
instead of claiming otherwise. Exact commands:
shared responsibility matrix.
Can I put CUI or ITAR-controlled data in GovConHouse?
The platform can store unclassified data including CUI, with the encryption above. It does not handle classified or ITAR-controlled data, and it is not a repository for them. The platform screens for ITAR relevance and screens documents for CUI; classification decisions are yours to make and defend.
How do I verify a FAR or DFARS clause citation?
The platform looks up clause text in its far_dfars_clauses catalog. Before
you use a citation in a binding document, verify it against the official text
at acquisition.gov (DFARS) or the eCFR (FAR). The catalog is a working
snapshot, not the source of record. See the
clause library.
Does the platform have enterprise SSO (SAML/OIDC)?
Not today. Login is email and password with role-based access (company administrator and team member) per company. Single sign-on is planned and not part of the current build.
Accounts and access
Section titled “Accounts and access”Who can see my company’s data?
Your company’s data is scoped to your company. Pipeline items, proposals, sentinel runs, audit events, and CMMC assessment rows are filtered to the caller’s supplier id, and cross-tenant reads return 404 by design. Admin users inside your company can see your company’s records; every write goes into an immutable audit trail. One known limitation is on record: legacy pre-2026-09-20 CMMC rows without a supplier id are filtered out of tenant-scoped reads and are queued for quarantine.
GovConHouse staff with platform administrator access can view customer data to provide support. Changes made through that access are recorded in the audit log. The Privacy Policy describes this access.
Does the platform use my data to train AI models?
No. AI runs in mock mode by default (AI_LIVE_CALLS_ENABLED=False); live AI
calls are off until explicitly enabled with an approved budget. The platform
does not train models on customer data. See
AI transparency.
Can I delete my account and data?
Yes, account deletion is supported. The launch path is a staged pilot with a small number of customers, and unused or test accounts are removed before open launch. Contact support inside the app to remove an account now.
How do roles and permissions work?
Two roles inside your company: company administrator and team member. Company administrators manage users, settings and billing; team members work in the platform without those controls. A third role, platform administrator, is held only by GovConHouse staff. Every protected route checks the role server-side, not just in the interface.
Data and sources
Section titled “Data and sources”Where does the opportunity data come from?
SAM.gov, USASpending, Grants.gov, DIBBS, FPDS, SBIR, and NSF. The sync tasks pull from these sources on a schedule, and every synced row keeps its source. DIBBS has no public API and is scraped; a daily smoke test alerts if it returns nothing.
Why does a closed notice still show as open?
That is a bug, and a fixed one. Source status is now mapped on ingest, so closed and archived notices do not appear as open in search, lists, or alerts. If you still see one, report it with the notice title.
How current is the clause catalog?
The catalog is a snapshot. The trust page shows its last sync date. Clause text is re-verified against acquisition.gov and the eCFR for anything you put in a binding document.
Proposals and documents
Section titled “Proposals and documents”Does the platform submit bids to SAM.gov for me?
No. The bid workflow drafts bids, and every bid stops at a human-review gate
(PENDING_REVIEW) before anything can go out. A person reviews and submits.
Submission through SAM.gov is yours.
Are the claims in generated proposals verified?
Generated text is not taken on faith. The reviewer agent decomposes proposal text into atomic claims and verifies each one against source material; unsupported claims are regenerated or flagged, and the verdicts are stored with the section. Measured results are published on the public trust page.
What is [NEEDS_INPUT: …] in my proposal?
It is the honest placeholder, not a failure. When a claim cannot be supported
by a source, the pipeline writes [NEEDS_INPUT: what is missing] instead of
guessing a value. Fill it in with a real number or reference before the
proposal goes anywhere.
Self-hosting, AI, and operations
Section titled “Self-hosting, AI, and operations”Can I self-host GovConHouse?
Yes. The platform ships as containers (backend, worker, beat, frontend, Postgres, Redis) with migrations that run on deploy. Hosted operation runs on Fly.io with external Postgres and Redis. You set the encryption keys on your own deployment; hosted operators set them on the hosted one.
Is the AI always on?
No. Mock AI is the default and costs nothing. Live AI calls stay off until the operator approves them with a budget, and spend is capped with a hard monthly limit.
What does “mock AI” produce?
Deterministic, clearly-labeled sample output. Mock mode exists so every workflow is exercisable without spending on model calls. Live mode produces real model output only after the operator enables it with an approved budget.
Which AI providers does the platform use?
Live calls route through the local Claude Code CLI by default; API backends (Anthropic, DeepSeek) exist as fallbacks behind the same spend controls. Embeddings use text-embedding-3-small and degrade to zero vectors, not crashes, when no key is set.
Billing and support
Section titled “Billing and support”How do I reach support?
Support lives inside the app. Account and access questions go there. Billing questions: billing@govconhouse.com.
Where is the product documentation?
Reference documentation for every feature: docs.govconhouse.com.