ABAC + Postgres RLS
Every row carries an org and resource attribute. Even a bad query cannot leak across tenants. The database itself refuses.
Tender data is sensitive: pricing, partner agreements, key personnel CVs. We built ProTender so even our own team needs a reason to touch your tenant.
Every row carries an org and resource attribute. Even a bad query cannot leak across tenants. The database itself refuses.
TLS 1.2+ for every byte, AES-256 at the storage layer, KMS-managed keys with annual rotation.
Bring Okta, Azure AD, Google Workspace, or any SAML 2.0 IdP. Provisioning and de-provisioning automated.
Your prompts and uploads are never used to train any model, ours or a vendor's. Bedrock is configured with opt-out.
Every AI action, edit, export, and access is recorded. The audit log is queryable and exportable.
On Enterprise, run the AI on your own Bedrock keys in your own AWS account. Spend, logs, and residency stay yours.
Last updated · June 2026
Every row in every table carries the organisation it belongs to. Postgres Row Level Security policies are applied to all tenant tables and validated on every deploy by an automated script that counts policy presence per table.
The application enforces attribute-based access control on top of RLS, so even within a tenant a reviewer cannot see drafts they are not assigned to.
All traffic between you, the platform, and the AI providers is encrypted with TLS 1.2 or higher. At rest, data is stored on AES-256 encrypted volumes; uploads to S3 use SSE-S3 by default and SSE-KMS with customer-managed keys on Enterprise.
ProTender uses Clerk for authentication. SAML SSO is supported on Growth and above, and required on Enterprise. SCIM provisioning and de-provisioning is available on Enterprise.
Every privileged action — sign-in, AI run, export, settings change, KB upload — is captured in an immutable, append-only audit log. Administrators can query and export the log from settings.
All inference runs through AWS Bedrock with the no-training flag enabled. Every drafted sentence is grounded by a retrieval pass against your KB. Sections cannot be marked “ready” until every claim has a verified citation. Hallucination risk is logged per section for review.
Every pull request runs typecheck, lint, unit tests, integration tests, container scan, and dependency-vulnerability scan. Secrets never live in the repository; rotation is automated via AWS Secrets Manager.
We follow a documented incident response runbook with on-call rotation, severity classification, and a 72-hour notification SLA for personal data breaches. Post-mortems are written for every severity-1 incident and shared with affected customers.
SOC 2 Type I evidence pack is available under NDA. SOC 2 Type II is in progress with a Q4 2026 target. ISO 27001 and a regional standard (PSPF for AU public-sector use cases) are on the roadmap for 2027.
A focused walkthrough on Zoom or Google Meet. We parse one of your real tenders and walk you through the compliance matrix, the draft, and the citation panel.