ProTender

Security & Trust

Built for tender data that cannot leak.

Org-scoped tenancy, ABAC, and RLS. Live vs planned scope stays in Known-Limitations.

  • Encrypted in transit and at rest.
  • No training on your data.
  • Human sign-off before export.

Org-scoped tenancy + ABAC

Organisation and role on every request. ABAC gates edit, approve, export.

Encrypted in transit and at rest

TLS for traffic. Server-side encryption on document storage.

Clerk authentication

Email and social via Clerk. SAML/SCIM planned before open self-serve.

No training on your data

Uploads never train our models. Bedrock runs with training opt-out.

Append-only audit log

Privileged actions write audit rows. Retention packs before GA.

Export readiness gates

Strict mode blocks export while citations stay unverified.

Trust

What is live in closed beta.

Last updated · July 2026

Tenant isolation

Application code scopes every business query to the active organisation. Postgres RLS policy templates exist on tenant tables. Closed beta may still connect with a privileged DATABASE_URL; that means RLS is prepared but not the sole enforcement layer until the tenderos_app cutover (see Known-Limitations and RLS_Tenant_Cutover).

Within an organisation, CASL ABAC (system role snapshot, optionally merged with seeded abac_* policies) gates tender, proposal, KB, and export actions.

Encryption

Traffic between browsers, Amplify, and AWS services uses TLS. Object storage uses server-side encryption. Operator secrets live in Amplify Console and EC2 env files, not in git.

Identity and SSO

ProTender uses Clerk for authentication today. Optional MFA for elevated roles can be forced with REQUIRE_MFA_FOR_ELEVATED=true. SAML SSO and SCIM provisioning are not sold as generally available in closed beta.

Audit log

Privileged product actions (AI runs, exports, KB uploads, settings changes) write append-only audit rows. A polished immutable-export UX for diligence packs is still on the roadmap.

AI guardrails

Inference runs through AWS Bedrock with training opt-out. Section drafts are grounded with KB retrieval and citation markers. Citation verification is enqueued after section write and must pass readiness gates (unsupported citations block export when PROPOSAL_STRICT_READINESS is on, the default). We do not claim 0% hallucination; quality is measured with deterministic gates and promptfoo fixtures in CI.

Secure SDLC

GitHub Actions runs typecheck, unit tests, and the model quality gate (citation verifier vitest + promptfoo fixtures). Amplify Hosting deploys from the connected branch; treat Known-Limitations as the deploy honesty contract for closed beta.

Incident response

Operators follow internal runbooks for severity classification and customer notification. Formal SOC 2 evidence packs are available under NDA when ready; do not treat this page as a completed certification claim.

Compliance roadmap

SOC 2 and related certifications are roadmap items, not closed-beta certifications. For diligence, start with Known-Limitations.md and Productization-Roadmap.md rather than marketing adjectives.

Closed beta

Bring a real RFP. See it scored live.

Invite-only. Request access, or book a walkthrough with your sample tender pack.

  • Share your org and a sample RFP
  • Focused session on eligibility, citations, export
  • No card. PO invoicing when you convert
Book a demo

Opens your email app with a prefilled message. We do not store this form server-side yet.