Security and data handling
Built for organizations that handle sensitive commercial information.
Tenant isolation
Every record is scoped to your organization and enforced at the database level with row-level security in addition to application authorization.
Private document storage
Uploaded files are stored privately with short-lived, authorization-checked download links. Archives are inspected before extraction.
AI with provenance
Tender documents are treated as untrusted input. Model outputs are validated against schemas and every generated statement is linked to its source.
Access control
Role-based permissions (Owner, Admin, Bid Manager, Member, Viewer), session management and audit logs for sensitive actions.
Transport and headers
TLS everywhere, strict content-security policy, rate limits and request size limits.
Retention and deletion
Organization deletion requests trigger a full purge of tenant data after a confirmation window.
Security questions or a disclosure to report? Use the contact page.