Skip to content
TenderOS AI for tenders & RFPs
Security

Secure RFP Software for Confidential Tenders

Your tender documents are company-confidential data, and a tender pack usually arrives with confidentiality obligations attached before you have decided whether to bid. Secure RFP software has to be built around that constraint rather than apologise for it afterwards.

The free analyzer never uploads anything

The ordinary free-tool bargain is that you send your document to a stranger's server in exchange for a result. For a confidential procurement pack, that is a bad trade — and it is the reason most bid teams cannot try tools on live work.

So the analyzer does not make that trade. Parsing, clause detection, date extraction and counting all run in JavaScript on your machine. There is no request carrying your document anywhere, and you can confirm that in your browser's network tab in about ten seconds.

The practical consequence: you can evaluate the tool on a live confidential tender today, without a data processing agreement, a security questionnaire or a procurement conversation first.

Try it on a live tender

What we do not claim

There is no SOC 2 badge, no ISO 27001 badge and no compliance seal anywhere on this site. None has been achieved yet, and advertising one before the audit completes would be precisely the unsupported claim this product is designed to prevent in your proposals.

The same rule applies to results. No percentage of time saved, no win-rate uplift, no adoption statistics. When verified customer measurements exist they will be published as case studies with the method attached.
Controls

Implemented controls in the paid platform

This list describes what the platform does, not what it aspires to. Future capabilities are named as future.

Transport encryption
All traffic is served over TLS. HTTP requests are redirected to HTTPS and HSTS is set with a long max-age.
Encryption at rest
Documents and extracted content are encrypted at rest in the storage layer.
Private object storage
Uploaded files have no permanent public URL. Access is granted through short-lived signed links generated per request.
Tenant isolation
Every object carries an organisation identifier and retrieval is filtered on it at query level, never in the interface. Cross-tenant access is covered by automated tests.
Role permissions
Owner, admin, bid manager, contributor, reviewer and viewer roles, enforced server-side.
Malware scanning
Uploads are scanned before parsing. Macros and embedded scripts in uploaded documents are never executed.
Isolated parsing
Document parsing runs in an isolated process so a malformed or hostile file cannot reach the wider system.
Prompt injection defence
All uploaded document text is treated as untrusted data. Instructions embedded in a tender or a company document cannot alter system behaviour.
Rate limiting and abuse controls
Request, upload and job limits protect both availability and cost.
Audit events
Material actions — upload, edit, approval, export, status change — are recorded. Full audit log access is a Pro and Enterprise capability.
Secret management
API keys, billing secrets and database credentials live in managed secret storage and are never committed to source control.
Backups
Database backups run on a schedule with restore testing.

Documents as untrusted input

A tender document is written by someone outside your organisation, and a company document may have passed through many hands. Either can contain text aimed at an AI system — "ignore previous instructions" and its many variations.

Every extraction and generation prompt therefore states that uploaded document text is data, never instruction, and that no content inside a document may alter system behaviour. The same rule applies to Company Brain material, which is sanitised and isolated on the same basis.

Analytics that carry no content

Product analytics record that an analysis completed, that a response was generated, that an export ran. They never carry tender text, requirement content, proposal responses, company documents or filenames that could disclose a confidential opportunity.

Error logging follows the same rule: payloads are redacted, and confidential document content is not written to logs in order to make debugging easier.

Questions

Security questions

Is TenderOS SOC 2 or ISO 27001 certified?
No, and you will not find a badge for either on this site. Publishing a certification before the audit is complete would be exactly the kind of unsupported claim the product exists to prevent. When a certification is achieved it will be stated here with its scope and date.
Does the free analyzer send my document anywhere?
No. It runs entirely in your browser using local JavaScript. The file is read from disk, parsed in memory and discarded when the tab closes. You can verify this yourself by opening your browser network tab while running an analysis — there is no request carrying the document.
Are our documents used to train AI models?
No. Customer tender documents and company knowledge are not used to train models. Where a third-party model provider is used for drafting, the account configuration is set so submitted content is excluded from training.
Where is our data stored?
In the platform’s primary region by default. Regional data storage for a specific jurisdiction is an Enterprise arrangement, agreed in contract rather than assumed.
What happens when we delete something?
Deletion propagates through object storage, the database, vector embeddings and cached extraction output, rather than simply hiding a record in the interface. You can delete an individual file, a tender, a Company Brain document or the whole organisation.
How long is data retained?
Paid organisations retain data while the account requires it, with configurable organisation retention periods available. Anonymous free-tool activity retains nothing at all, because nothing is transmitted in the first place.
Can an administrator read our tender documents?
The internal admin tooling is scoped to operational data — organisations, subscriptions, usage, job failures, model errors and cost. It is not a document browser, and customer document contents are not exposed to staff as a matter of routine.

Enterprise security review, data processing terms or a completed vendor questionnaire? Talk to us — and if you are on the other side of that process, our guide to security questionnaire automation may be useful.

Analyze a Tender Free