ProTender
Security & trust

Procurement-grade trust from day one.

Tender data is sensitive: pricing, partner agreements, key personnel CVs. We built ProTender so even our own team needs a reason to touch your tenant.

  • Hosted on AWS, with data residency in your region of choice.
  • No training on your data, by any party.
  • Evidence pack and DPA available under NDA for enterprise reviews.

ABAC + Postgres RLS

Every row carries an org and resource attribute. Even a bad query cannot leak across tenants. The database itself refuses.

Encrypted in transit and at rest

TLS 1.2+ for every byte, AES-256 at the storage layer, KMS-managed keys with annual rotation.

SSO via Clerk

Bring Okta, Azure AD, Google Workspace, or any SAML 2.0 IdP. Provisioning and de-provisioning automated.

No training on your data

Your prompts and uploads are never used to train any model, ours or a vendor's. Bedrock is configured with opt-out.

Immutable audit log

Every AI action, edit, export, and access is recorded. The audit log is queryable and exportable.

BYO AWS account

On Enterprise, run the AI on your own Bedrock keys in your own AWS account. Spend, logs, and residency stay yours.

Trust

Security in depth.

Last updated · June 2026

Tenant isolation

Every row in every table carries the organisation it belongs to. Postgres Row Level Security policies are applied to all tenant tables and validated on every deploy by an automated script that counts policy presence per table.

The application enforces attribute-based access control on top of RLS, so even within a tenant a reviewer cannot see drafts they are not assigned to.

Encryption

All traffic between you, the platform, and the AI providers is encrypted with TLS 1.2 or higher. At rest, data is stored on AES-256 encrypted volumes; uploads to S3 use SSE-S3 by default and SSE-KMS with customer-managed keys on Enterprise.

Identity and SSO

ProTender uses Clerk for authentication. SAML SSO is supported on Growth and above, and required on Enterprise. SCIM provisioning and de-provisioning is available on Enterprise.

Audit log

Every privileged action — sign-in, AI run, export, settings change, KB upload — is captured in an immutable, append-only audit log. Administrators can query and export the log from settings.

AI guardrails

All inference runs through AWS Bedrock with the no-training flag enabled. Every drafted sentence is grounded by a retrieval pass against your KB. Sections cannot be marked “ready” until every claim has a verified citation. Hallucination risk is logged per section for review.

Secure SDLC

Every pull request runs typecheck, lint, unit tests, integration tests, container scan, and dependency-vulnerability scan. Secrets never live in the repository; rotation is automated via AWS Secrets Manager.

Incident response

We follow a documented incident response runbook with on-call rotation, severity classification, and a 72-hour notification SLA for personal data breaches. Post-mortems are written for every severity-1 incident and shared with affected customers.

Compliance roadmap

SOC 2 Type I evidence pack is available under NDA. SOC 2 Type II is in progress with a Q4 2026 target. ISO 27001 and a regional standard (PSPF for AU public-sector use cases) are on the roadmap for 2027.

Demo

Bring a real RFP. Watch us draft it in front of you.

A focused walkthrough on Zoom or Google Meet. We parse one of your real tenders and walk you through the compliance matrix, the draft, and the citation panel.

How demos work
  • Email us with your organisation and a sample RFP if you can share one.
  • We schedule a 20-minute session that fits your timezone.
  • Cal.com self-serve booking will replace email scheduling soon.
hello@protender.biz