Security & trust

Security enforced on the server, not just hidden in the browser

Every API checks the user, agency, role, record and tender stage before acting. Hiding a button is never the only safeguard.

How a bid stays sealed

From submission to opening

  1. 1

    Seal

    The supplier encrypts each envelope in the bid vault and receives a submission receipt.

  2. 2

    Close

    At the deadline the submission window closes on its own. Late bids aren’t accepted.

  3. 3

    Attend

    Committee key holders join the opening session and verify with a second factor.

  4. 4

    Open

    Enough key shares decrypt the technical envelope. Financial envelopes wait for qualification.

  5. 5

    Record

    Opening minutes are frozen at sign-off, and every later view or download is logged.

Controls

Controls you can show an auditor

Dual-lock bid vault

Bid envelopes are encrypted at submission. Decryption needs key shares held by the sitting committee and custody through a KMS. Keys never exist in one place.

Hash-chained audit log

Each audit event links to the one before it, so tampering shows. Creating, publishing, opening, scoring, approving, downloading and changing a role are all recorded.

Segregation of duties

The person who prepares a record can’t approve it. Evaluators are kept out of award approval, and the opening team comes from the tender’s committee.

Upload hygiene

File type and size checks, malware scanning, tenant ownership and versioned documents. Files are served through access-checked endpoints, never through raw storage URLs.

Tenant isolation

Queries are tenant-aware and authorisation is checked at record level. The codebase has been audited against cross-tenant references and ID guessing.

Reliable events

Business events are published through a transactional outbox, so notifications and integrations never run ahead of the data they describe.

Deployment

Your infrastructure, your data

Sovereign or private cloud

Runs as containers on your own infrastructure or national cloud. PostgreSQL, Redis, S3-compatible storage and an event bus, all open components.

Kubernetes-ready

Stateless API and workers, health checks, unprivileged images and configuration through the environment, ready for your cluster.

Need a security walkthrough for your review board?

We can present the bid-vault design, audit chain and tenant isolation model to your security and audit teams.