Skip to content

Security and data handling

Built for organizations that handle sensitive commercial information.

Tenant isolation

Every record is scoped to your organization and enforced at the database level with row-level security in addition to application authorization.

Private document storage

Uploaded files are stored privately with short-lived, authorization-checked download links. Archives are inspected before extraction.

AI with provenance

Tender documents are treated as untrusted input. Model outputs are validated against schemas and every generated statement is linked to its source.

Access control

Role-based permissions (Owner, Admin, Bid Manager, Member, Viewer), session management and audit logs for sensitive actions.

Transport and headers

TLS everywhere, strict content-security policy, rate limits and request size limits.

Retention and deletion

Organization deletion requests trigger a full purge of tenant data after a confirmation window.

Security questions or a disclosure to report? Use the contact page.