Sealed bids
Submissions are sealed with tamper-evident timestamps and SHA-256 file hashes — nothing is opened before the deadline.
Procurement runs on trust. These are the controls we build in by default — because a bid platform is only as good as the integrity it guarantees.
Submissions are sealed with tamper-evident timestamps and SHA-256 file hashes — nothing is opened before the deadline.
Every material action is written to an append-only record, exportable for inspection.
Submit, publish, award, and spend always require an explicit human decision. AI assists up to the gate; people decide.
Role-based access with least privilege, SSO/SAML, and support for UAE PASS and Nafath.
Encryption in transit (TLS) and at rest. Hardened HTTP security headers (CSP, HSTS, COOP) on every response.
Security headers enforced in production; penetration testing and a SOC 2 pathway as we scale.
Your data is pinned to its region — EU/Frankfurt, Canada, or the US today — and does not leave without a documented basis. In-country hosting (UAE/KSA and others) is available on request.
GDPR, the GCC PDPLs (UAE, Saudi, Qatar, Oman, Bahrain), and, in North America, PIPEDA and Québec Law 25 — with US state laws and a SOC 2 posture.
Data access, export, and erasure are self-serve. Records of processing and a DPA are available.
Every win-score lists its drivers; every AI-drafted paragraph cites its source in the tender documents.
AI is decision-support only. It never awards a contract — a human always decides.
Proposals are generated from the tender requirements and your own content, with citations — not hallucinated commitments.
Our guides and data pages are written to be accurate and vendor-neutral. We verify facts against current sources rather than asserting them from memory, we never fabricate statistics or ratings, and our published data is aggregated and anonymized (k-anonymity) so no individual bid is identifiable. Where we compare ourselves to other tools, we do so on capability, not invented pricing.