Org-scoped tenancy + ABAC
Organisation and role on every request. ABAC gates edit, approve, export.
Security & Trust
Org-scoped tenancy, ABAC, and RLS. Live vs planned scope stays in Known-Limitations.
Organisation and role on every request. ABAC gates edit, approve, export.
TLS for traffic. Server-side encryption on document storage.
Email and social via Clerk. SAML/SCIM planned before open self-serve.
Uploads never train our models. Bedrock runs with training opt-out.
Privileged actions write audit rows. Retention packs before GA.
Strict mode blocks export while citations stay unverified.
Last updated · July 2026
Application code scopes every business query to the active organisation. Postgres RLS policy templates exist on tenant tables. Closed beta may still connect with a privileged DATABASE_URL; that means RLS is prepared but not the sole enforcement layer until the tenderos_app cutover (see Known-Limitations and RLS_Tenant_Cutover).
Within an organisation, CASL ABAC (system role snapshot, optionally merged with seeded abac_* policies) gates tender, proposal, KB, and export actions.
Traffic between browsers, Amplify, and AWS services uses TLS. Object storage uses server-side encryption. Operator secrets live in Amplify Console and EC2 env files, not in git.
ProTender uses Clerk for authentication today. Optional MFA for elevated roles can be forced with REQUIRE_MFA_FOR_ELEVATED=true. SAML SSO and SCIM provisioning are not sold as generally available in closed beta.
Privileged product actions (AI runs, exports, KB uploads, settings changes) write append-only audit rows. A polished immutable-export UX for diligence packs is still on the roadmap.
Inference runs through AWS Bedrock with training opt-out. Section drafts are grounded with KB retrieval and citation markers. Citation verification is enqueued after section write and must pass readiness gates (unsupported citations block export when PROPOSAL_STRICT_READINESS is on, the default). We do not claim 0% hallucination; quality is measured with deterministic gates and promptfoo fixtures in CI.
GitHub Actions runs typecheck, unit tests, and the model quality gate (citation verifier vitest + promptfoo fixtures). Amplify Hosting deploys from the connected branch; treat Known-Limitations as the deploy honesty contract for closed beta.
Operators follow internal runbooks for severity classification and customer notification. Formal SOC 2 evidence packs are available under NDA when ready; do not treat this page as a completed certification claim.
SOC 2 and related certifications are roadmap items, not closed-beta certifications. For diligence, start with Known-Limitations.md and Productization-Roadmap.md rather than marketing adjectives.
Closed beta
Invite-only. Request access, or book a walkthrough with your sample tender pack.