Encrypted in transit
All traffic is served over TLS 1.2+ with HSTS enforced, including preload. There is no unencrypted path to the application.
Your bid is your commercial position. It stays yours — stored in India, isolated from every other customer, and never used to train a model.
Last updated 12 August 2026
Your tenders are never used to train or fine-tune any model — ours or our providers'. No toggle, no exceptions.
Database, documents, search indexes and backups all held in the AWS Asia Pacific (Mumbai) region.
Close your account and everything — records, files and derived embeddings — is removed within 30 days.
Every extracted fact, risk flag and verdict links back to the exact clause and page it came from.
We publish exactly what is in place today and what is still in progress. You should be able to check a vendor's claims — so we only make ones you can.
| Framework | Scope | Status |
|---|---|---|
| DPDP Act, 2023 | India — personal data protection | Aligned |
| GDPR / UK GDPR | EU & UK — SCCs and UK Addendum in our DPA | Aligned |
| ISO 27001 | Information security management system | Certification underway |
| SOC 2 Type II | Security, availability and confidentiality | Planned |
| CCPA / CPRA | California — we do not sell or share personal information | Aligned |
ISO 27001 certification is underway; SOC 2 Type II follows. We will publish the certificate date and scope here the day it is issued — and not before. If your procurement process needs evidence today, email engineering@bidlyft.com and we will complete your security questionnaire.
Four groups of controls, each doing a different job — so no single failure exposes a tender.
Your tender pack is commercially sensitive — often while your competitors are bidding the same tender. It is treated that way at every layer.
All traffic is served over TLS 1.2+ with HSTS enforced, including preload. There is no unencrypted path to the application.
Databases, uploaded documents and backups are encrypted at rest with AES-256.
Every record is scoped to a team. Retrieval, search and generation are constrained to your team's data — one workspace cannot read another's content, and the isolation is enforced in the data layer rather than the UI.
Passwords are stored only as bcrypt hashes and never in plain text or in logs. Sessions are signed and server-validated.
Export your content at any time, in full. Your data stays yours, and leaving does not mean losing it.
Deletion covers the primary database, file storage and the vector embeddings derived from your documents — then ages out of encrypted backups within the backup cycle. No shadow copies.
AI reads your tender. That makes how the AI is governed a security question, not a product one — so we answer it directly.
Not by us, and not by our model providers — their enterprise terms prohibit it contractually. This is a standing commitment we will not change without notice and the ability to leave.
Retrieval is scoped per team. No part of your pricing, strategy or proposal text can surface in another customer's generated output.
Extracts sent for analysis are used solely to return our result and are not retained by the provider for their own purposes.
Outputs are anchored to the source document. Every material finding carries a clause and page reference so a reviewer can verify rather than trust.
AI drafts the assessment; your configured rules determine the Go/No-Go verdict. The audit trail records which did which.
We do not make decisions producing legal or similarly significant effects about individuals by automated means alone.
Who did what, to which bid, and when — recorded and exportable, because public-sector and enterprise buyers will ask you to prove it.
Granular roles across the workspace so contributors, reviewers and approvers see only what their role requires.
Security-relevant actions are logged with actor, action, target and timestamp — retained for 24 months and exportable for your own audits.
Administrative access is restricted to named personnel who require it, and is itself logged.
No-Go decisions route through approval rather than being dropped silently — every call ends up on the record.
Everyone with access to production is bound by written confidentiality obligations.
Optional SSO for teams that centralise identity, so account lifecycle follows your directory.
Hardened defaults, applied consistently rather than selectively.
Infrastructure runs in the AWS Asia Pacific (Mumbai) region. Data is not replicated outside the country.
Content-Security-Policy, HSTS with preload, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a restrictive Permissions-Policy are applied across the application.
Every public endpoint validates and bounds its input server-side — types, lengths and allowed values — regardless of what the client sent.
Unauthenticated endpoints are rate-limited per client with request-size caps, so scripted abuse is contained before it reaches the database.
All database access goes through a typed query layer, eliminating string-concatenated SQL as a class of vulnerability.
Automated encrypted backups on a rolling cycle, with restores exercised rather than assumed.
Database, uploaded documents, search indexes and backups are all held in the AWS Asia Pacific (Mumbai) region, and are not replicated outside the country.
We chose this deliberately. Indian public-sector and PSU tenders increasingly require it — and your bid documents are commercially sensitive in a market where your competitors are often bidding the same tender.
If a specific tender or internal policy imposes additional residency or processing requirements, tell us before you upload and we will confirm in writing what we can meet.
Service providers act only on our instructions, under written contract. We give 30 days' notice before adding a new one that handles your content.
No. We do not train, fine-tune or evaluate any model on your content, and our model providers are contractually prohibited from doing so. There is no setting that changes this, and we will not change the commitment without giving notice and the ability to leave.
In India. Our infrastructure runs in the AWS Asia Pacific (Mumbai) region — database, uploaded documents, search indexes and backups. Data is not replicated outside the country.
No. Every record is scoped to your team and isolation is enforced in the data layer. Retrieval and generation only ever run against your own team's content, so nothing of yours can appear in another customer's output.
Not yet, and we will not claim it before it is true. Our controls are built to align with both frameworks — access control, audit logging, encryption, sub-processor governance, retention discipline and incident response — and ISO 27001 certification is underway. We will publish the date and scope here once certified. If you need evidence now, we will complete your security questionnaire.
Export everything first — in full, at any time. On account closure or a written deletion request, your records, files and the embeddings derived from your documents are deleted within 30 days, then age out of encrypted backups within the backup cycle.
You check it. Every material output carries a citation to the exact clause and page it came from, so verification takes seconds rather than a re-read. AI drafts the assessment; your configured rules decide the verdict; the audit trail records both.
Yes. Optional single sign-on, plus granular roles across the workspace so contributors, reviewers and approvers see only what their role requires. Security-relevant actions are audit-logged and exportable.
Email engineering@bidlyft.com with the details and reproduction steps. We acknowledge within 3 business days, keep you updated while we investigate, and will not pursue action against good-faith research that respects customer data.
Email engineering@bidlyft.com with details and reproduction steps. We acknowledge within 3 business days and keep you updated while we investigate.
We will not pursue action against good-faith research that respects customer data and avoids privacy violations, service degradation or data destruction.
We complete vendor security assessments, share our documentation, and will sign a DPA. Bring your infosec team to the demo — the questions are the point.