BidLyft
Log inRequest a demo
Security & trust

Safe to put your most confidential tenders through.

Your bid is your commercial position. It stays yours — stored in India, isolated from every other customer, and never used to train a model.

Talk to us about securitySee the controls

Last updated 12 August 2026

Never

Trained on your data

Your tenders are never used to train or fine-tune any model — ours or our providers'. No toggle, no exceptions.

India

Data residency

Database, documents, search indexes and backups all held in the AWS Asia Pacific (Mumbai) region.

30 days

To full deletion

Close your account and everything — records, files and derived embeddings — is removed within 30 days.

100%

Traceable to source

Every extracted fact, risk flag and verdict links back to the exact clause and page it came from.

Where we stand

Compliance posture, stated honestly.

We publish exactly what is in place today and what is still in progress. You should be able to check a vendor's claims — so we only make ones you can.

FrameworkScopeStatus
DPDP Act, 2023India — personal data protectionAligned
GDPR / UK GDPREU & UK — SCCs and UK Addendum in our DPAAligned
ISO 27001Information security management systemCertification underway
SOC 2 Type IISecurity, availability and confidentialityPlanned
CCPA / CPRACalifornia — we do not sell or share personal informationAligned

ISO 27001 certification is underway; SOC 2 Type II follows. We will publish the certificate date and scope here the day it is issued — and not before. If your procurement process needs evidence today, email engineering@bidlyft.com and we will complete your security questionnaire.

The controls

Defence in depth, layer by layer.

Four groups of controls, each doing a different job — so no single failure exposes a tender.

Data protection

Your tender pack is commercially sensitive — often while your competitors are bidding the same tender. It is treated that way at every layer.

Encrypted in transit

All traffic is served over TLS 1.2+ with HSTS enforced, including preload. There is no unencrypted path to the application.

Encrypted at rest

Databases, uploaded documents and backups are encrypted at rest with AES-256.

Tenant isolation

Every record is scoped to a team. Retrieval, search and generation are constrained to your team's data — one workspace cannot read another's content, and the isolation is enforced in the data layer rather than the UI.

Credential handling

Passwords are stored only as bcrypt hashes and never in plain text or in logs. Sessions are signed and server-validated.

Data export

Export your content at any time, in full. Your data stays yours, and leaving does not mean losing it.

Verified deletion

Deletion covers the primary database, file storage and the vector embeddings derived from your documents — then ages out of encrypted backups within the backup cycle. No shadow copies.

AI safety

AI reads your tender. That makes how the AI is governed a security question, not a product one — so we answer it directly.

No training on customer content

Not by us, and not by our model providers — their enterprise terms prohibit it contractually. This is a standing commitment we will not change without notice and the ability to leave.

No cross-customer leakage

Retrieval is scoped per team. No part of your pricing, strategy or proposal text can surface in another customer's generated output.

Processed, not retained

Extracts sent for analysis are used solely to return our result and are not retained by the provider for their own purposes.

Grounded and cited

Outputs are anchored to the source document. Every material finding carries a clause and page reference so a reviewer can verify rather than trust.

Human decision, machine draft

AI drafts the assessment; your configured rules determine the Go/No-Go verdict. The audit trail records which did which.

No automated decisions about people

We do not make decisions producing legal or similarly significant effects about individuals by automated means alone.

Access & accountability

Who did what, to which bid, and when — recorded and exportable, because public-sector and enterprise buyers will ask you to prove it.

Role-based access control

Granular roles across the workspace so contributors, reviewers and approvers see only what their role requires.

Audit logging

Security-relevant actions are logged with actor, action, target and timestamp — retained for 24 months and exportable for your own audits.

Least-privilege administration

Administrative access is restricted to named personnel who require it, and is itself logged.

Approval workflows

No-Go decisions route through approval rather than being dropped silently — every call ends up on the record.

Confidentiality obligations

Everyone with access to production is bound by written confidentiality obligations.

Single sign-on

Optional SSO for teams that centralise identity, so account lifecycle follows your directory.

Infrastructure & application security

Hardened defaults, applied consistently rather than selectively.

Indian region hosting

Infrastructure runs in the AWS Asia Pacific (Mumbai) region. Data is not replicated outside the country.

Security headers enforced

Content-Security-Policy, HSTS with preload, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and a restrictive Permissions-Policy are applied across the application.

Input validation at the boundary

Every public endpoint validates and bounds its input server-side — types, lengths and allowed values — regardless of what the client sent.

Abuse controls

Unauthenticated endpoints are rate-limited per client with request-size caps, so scripted abuse is contained before it reaches the database.

Parameterised data access

All database access goes through a typed query layer, eliminating string-concatenated SQL as a class of vulnerability.

Encrypted, tested backups

Automated encrypted backups on a rolling cycle, with restores exercised rather than assumed.

Data residency

Your tender data stays in India.

Database, uploaded documents, search indexes and backups are all held in the AWS Asia Pacific (Mumbai) region, and are not replicated outside the country.

We chose this deliberately. Indian public-sector and PSU tenders increasingly require it — and your bid documents are commercially sensitive in a market where your competitors are often bidding the same tender.

If a specific tender or internal policy imposes additional residency or processing requirements, tell us before you upload and we will confirm in writing what we can meet.

Who processes your data

Service providers act only on our instructions, under written contract. We give 30 days' notice before adding a new one that handles your content.

Cloud infrastructure
Hosting, database, storage, backups
India (Mumbai)
AI processing
Document analysis, extraction, generation
Enterprise terms; no training
Identity provider
Optional single sign-on
Global
Email delivery
Transactional and notification email
US/EU
Payment processor
Billing for paid plans
India
Questions we get asked

The procurement and infosec questions, answered.

Do you train your AI models on our tender documents?

No. We do not train, fine-tune or evaluate any model on your content, and our model providers are contractually prohibited from doing so. There is no setting that changes this, and we will not change the commitment without giving notice and the ability to leave.

Where is our data stored?

In India. Our infrastructure runs in the AWS Asia Pacific (Mumbai) region — database, uploaded documents, search indexes and backups. Data is not replicated outside the country.

Can another company using BidLyft see our bids?

No. Every record is scoped to your team and isolation is enforced in the data layer. Retrieval and generation only ever run against your own team's content, so nothing of yours can appear in another customer's output.

Are you ISO 27001 or SOC 2 certified?

Not yet, and we will not claim it before it is true. Our controls are built to align with both frameworks — access control, audit logging, encryption, sub-processor governance, retention discipline and incident response — and ISO 27001 certification is underway. We will publish the date and scope here once certified. If you need evidence now, we will complete your security questionnaire.

What happens to our data if we leave?

Export everything first — in full, at any time. On account closure or a written deletion request, your records, files and the embeddings derived from your documents are deleted within 30 days, then age out of encrypted backups within the backup cycle.

How do we know an AI answer is right?

You check it. Every material output carries a citation to the exact clause and page it came from, so verification takes seconds rather than a re-read. AI drafts the assessment; your configured rules decide the verdict; the audit trail records both.

Do you support SSO and role-based access?

Yes. Optional single sign-on, plus granular roles across the workspace so contributors, reviewers and approvers see only what their role requires. Security-relevant actions are audit-logged and exportable.

How do we report a vulnerability?

Email engineering@bidlyft.com with the details and reproduction steps. We acknowledge within 3 business days, keep you updated while we investigate, and will not pursue action against good-faith research that respects customer data.

Responsible disclosure

Found something? Tell us.

Email engineering@bidlyft.com with details and reproduction steps. We acknowledge within 3 business days and keep you updated while we investigate.

We will not pursue action against good-faith research that respects customer data and avoids privacy violations, service degradation or data destruction.

Security review

Send us your questionnaire.

We complete vendor security assessments, share our documentation, and will sign a DPA. Bring your infosec team to the demo — the questions are the point.