All resourcesArticles · 6 min read

How a sealed bid vault prevents early bid disclosure

Early access to bids is one of the hardest procurement risks to detect. Here is how cryptographic sealing and shared keys turn a procedural safeguard into a technical one.

Most procurement rules say that bids must not be opened before the official opening time. In many organisations that rule is enforced by trust: an administrator who could read submissions agrees not to. The risk is not only actual leaks but the inability to prove there weren’t any when a losing bidder complains.

From “nobody should” to “nobody can”

A sealed bid vault changes the question. Instead of controlling who is allowed to look, it makes looking impossible until the right conditions are met. Each envelope is encrypted when the supplier submits it. The key needed to decrypt it is not held by any single person or system.

Shared keys, held by the committee

The decryption key is split into shares held by the tender’s committee members. Opening requires a minimum number of those shares to come together during the opening session. A single administrator, a single committee member or the system operator cannot open the vault alone.

  • Key holders follow the committee: if a member is replaced, their share is not carried over.
  • Key holders confirm their presence with a second factor, such as a passkey, before attendance is recorded.
  • Opening is only possible after the submission deadline has passed.

What it means after opening

Opening is not the end of control. Once decrypted, bid documents are still only available to people whose role and the tender stage allow it. Every view and download is logged, so the record shows who saw what, and when.

What to ask any vendor

  • Who, technically, could read a bid before the opening time? Include administrators and the vendor’s own staff.
  • Is decryption tied to the committee, or to a system account?
  • What happens to the keys of a committee member who is replaced?
  • Can the opening minutes be edited after sign-off?
  • Can you show me the access log for a single bid document?

In DigiProcure

DigiProcure’s dual-lock vault encrypts envelopes at submission, distributes key shares only to the sitting voting members of the committee, and requires a passkey confirmation at opening. Key custody is backed by a key management service, so keys never exist in one place.

See it run with your own procurement rules

We’ll go through a full tender, from plan to published award, configured for your thresholds, committees and approval chain.