Skip to main content
Security

Enterprise-grade by default.

Your bid strategy is the most sensitive data in your firm. We treat it that way, from the database schema up to the AI gateway.

Tenant isolation

Every table, storage prefix, and AI request is scoped by tenant_id. Row-level security enforces isolation at the database, not just the app layer, so a bug in a request handler cannot leak another workspace's data.

Encryption

TLS 1.2+ in transit and AES-256 at rest across the entire platform, including AI request payloads, generated documents, and object storage.

MFA on privileged actions

Sending submissions, issuing refunds, and exporting cross-workspace data require fresh MFA and a written reason, both recorded on the governance trail.

Audit & retention

Every state change writes to an immutable governance log. Retention is configurable per plan; delete-workspace erases all customer data within 24 hours.

Operational controls

How we run the platform.

Least-privilege access

Engineering access to production data is broker-mediated, time-boxed, and logged. No standing access to customer content.

Vetted sub-processors

AI inference runs through vetted gateways with zero-retention terms. Storage and compute sit with tier-1 EU-region providers.

Your data is not training data

We do not train shared models on your proposals, knowledge base, or generated content. Full stop.

Incident response

24-hour breach notification commitment. Runbooks, on-call rotation, and post-incident reviews shared with affected customers.

Compliance

Frameworks & certifications.

We publish our roadmap honestly. If a control is aspirational rather than certified, we say so.

GDPR

EU data residency, DPA on request, data subject requests fulfilled within statutory windows.

SOC 2 (in progress)

Type I readiness underway with a Big Four auditor. Type II window opens Q4 2026.

ISO 27001 aligned

Controls mapped to ISO 27001 Annex A; formal certification tracked on the same roadmap as SOC 2 Type II.

Report a vulnerability.

Found something concerning? Email security@contracttenders.com. We acknowledge within one business day, and we do not pursue researchers acting in good faith.