Federal contractor data security, stated plainly
Contractors handle sensitive pipeline information, so this page says what we do with yours rather than showing badges. If your security team needs more detail than this, write to [email protected].
The data we actually hold about you
We deliberately hold very little, because the product runs on public procurement records rather than on anything confidential of yours.
- Your work email address and the members of your team you invite
- Your company profile: NAICS codes, capability line, past performance entries, set-aside status, geography and contract size band
- Your saved searches, your bid board and the bid or no-bid decisions you record
- Usage records needed to run the service and to bill it
We do not ask for and do not want your proposal text, your pricing models, your rate cards, your teaming agreements or any material marked controlled or classified. The product does not need them to score a solicitation against your profile.
The solicitation data itself is public
Every solicitation and award record in the product comes from published public procurement sources: federal solicitation and award data published by the United States government, plus state, county and municipal bid boards. It is public before it reaches us and it stays public afterwards. Your profile, which is the private part, never leaves your account.
Who can see what
- Data is segregated per customer account. One account cannot read another account's profile, searches, board or exports.
- Roles and permissions per business line on Capture and Enterprise, so a team lead sees their pipeline and not the whole company's.
- SSO with SAML and OIDC on Enterprise, so access follows your identity provider and ends when you deprovision a person.
- An audit log on Enterprise covering profile changes, bid decisions, exports and access events.
- Our own staff access to customer data is limited to support work you have asked for, and it is logged.
Storage, transport and backups
- Traffic between you and the service runs over TLS.
- Data at rest is encrypted, and credentials are stored hashed rather than in a recoverable form.
- Backups are encrypted and access to them follows the same controls as the live system.
- Infrastructure sits with established providers under their own physical and network controls.
Retention and deletion
- Your profile, searches and board live as long as your account does.
- Canceling stops the renewal and leaves access running to the end of the period you paid for, so you can export what you need.
- Ask us to delete your account and we delete the profile, searches, board and decision history, with backups aging out on their normal cycle.
- We never sell your data, never pool it into a shared dataset and never use it to advertise to anyone.
What your security reviewer usually asks
Do you use our data to train anything
No. Your profile and your bid decisions are used to produce your matches and nothing else. They are not pooled across accounts and they are not sold.
Is there a single sentence explaining your model use
One narrow function writes the plain English explanation of a match on top of the deterministic score. It works on the public solicitation text and your profile fields. The scoring itself is arithmetic in our own code and runs with no external service at all.
Can we run a security review before we buy
Yes, on Enterprise, alongside invoicing and purchase orders. Write to [email protected] and we will work through your questionnaire.
Where do we report a vulnerability
Write to [email protected] with the details. We answer, we fix, and we tell you when it is fixed.