Trust Center

Built for the confidentiality your bids demand.

This page is maintained by BidForge to answer common security, privacy and compliance questions about the platform. It describes controls that are currently in place — not a certification.

Secure authentication

Email/password with strong password enforcement, plus Google single sign-on. Session tokens are managed by Supabase Auth.

Encrypted storage

Uploaded documents are stored in a private, access-controlled bucket. Data is encrypted at rest by the underlying platform.

Row-level security

Every table enforces per-user and per-organisation access rules at the database layer, not just in application code.

Organisation permissions

Business and Enterprise workspaces separate owners, admins and members. Only invited teammates can see shared documents and analyses.

Secure file handling

Uploads are validated by type and size before analysis. Signed URLs scope any file access to the requesting user.

Managed infrastructure

Built on Supabase and Cloudflare Workers. Databases and edge functions are patched and hardened by the platform.

No training on your data

Uploaded documents are used only to analyse your submission. They are not shared with third parties for AI model training.

Deletion on request

You can delete individual analyses at any time. Contact us for account-level deletion and we'll remove your data in line with our privacy policy.

Shared responsibility

BidForge is responsible for platform security, encryption, access control and the safe operation of AI analysis. Customers are responsible for the accuracy of the data they upload, for managing who they invite to their organisation workspace, and for ensuring the submissions they produce meet the requirements of the opportunities they respond to.

Reporting a security concern

If you believe you've identified a vulnerability, please contact us through the contact page. We take reports seriously and investigate promptly.