Security
Security for sensitive tender work
Tender documents and company evidence can contain commercially sensitive information. TenderFaro uses layered application controls to limit access and preserve accountable review.
Tenant isolation and private storage
Customer records are scoped to an organization. Database row-level security and server-side authorization enforce tenant boundaries. Uploaded tender and evidence files use private storage and are accessed through authenticated application flows rather than permanent public URLs.
Authentication and administrative access
Supabase Auth manages user sessions. Workspace and platform-administration routes require server-side authorization. Platform administration has separate roles and permissions, and sensitive administrative actions are designed for auditability.
AI processing and human review
AI provider credentials remain server-side. TenderFaro stores structured findings and source references so reviewers can inspect the basis of an output. AI findings may be incomplete or wrong and require human review before a bid decision.
Web and upload protections
The application applies restrictive browser security headers, private-route indexing controls, upload type and size validation, document fingerprints, and sanitized provider errors. Infrastructure firewall and rate-limit rules complement application controls after deployment.
Accurate security claims
This page describes implemented design and application controls. TenderFaro does not claim an external certification, security audit, or compliance status that has not been independently completed.