Security for sensitive tender work

Tender documents and company evidence can contain commercially sensitive information. TenderFaro uses layered application controls to limit access and preserve accountable review.

Tenant isolation and private storage

Customer records are scoped to an organization. Database row-level security and server-side authorization enforce tenant boundaries. Uploaded tender and evidence files use private storage and are accessed through authenticated application flows rather than permanent public URLs.

Authentication and administrative access

Supabase Auth manages user sessions. Workspace and platform-administration routes require server-side authorization. Platform administration has separate roles and permissions, and sensitive administrative actions are designed for auditability.

AI processing and human review

AI provider credentials remain server-side. TenderFaro stores structured findings and source references so reviewers can inspect the basis of an output. AI findings may be incomplete or wrong and require human review before a bid decision.

Web and upload protections

The application applies restrictive browser security headers, private-route indexing controls, upload type and size validation, document fingerprints, and sanitized provider errors. Infrastructure firewall and rate-limit rules complement application controls after deployment.

Accurate security claims

This page describes implemented design and application controls. TenderFaro does not claim an external certification, security audit, or compliance status that has not been independently completed.

Learn what TenderFaro does