Your bid strategy is the most sensitive data in your firm. We treat it that way, from the database schema up to the AI gateway.
Every table, storage prefix, and AI request is scoped by tenant_id. Row-level security enforces isolation at the database, not just the app layer, so a bug in a request handler cannot leak another workspace's data.
TLS 1.2+ in transit and AES-256 at rest across the entire platform, including AI request payloads, generated documents, and object storage.
Sending submissions, issuing refunds, and exporting cross-workspace data require fresh MFA and a written reason, both recorded on the governance trail.
Every state change writes to an immutable governance log. Retention is configurable per plan; delete-workspace erases all customer data within 24 hours.
Engineering access to production data is broker-mediated, time-boxed, and logged. No standing access to customer content.
AI inference runs through vetted gateways with zero-retention terms. Storage and compute sit with tier-1 EU-region providers.
We do not train shared models on your proposals, knowledge base, or generated content. Full stop.
24-hour breach notification commitment. Runbooks, on-call rotation, and post-incident reviews shared with affected customers.
We publish our roadmap honestly. If a control is aspirational rather than certified, we say so.
EU data residency, DPA on request, data subject requests fulfilled within statutory windows.
Type I readiness underway with a Big Four auditor. Type II window opens Q4 2026.
Controls mapped to ISO 27001 Annex A; formal certification tracked on the same roadmap as SOC 2 Type II.
Found something concerning? Email security@contracttenders.com. We acknowledge within one business day, and we do not pursue researchers acting in good faith.