Back to Home

Security and Deployment

Run bid evaluation in your private cloud or on your own infrastructure.

Keep supplier documents, extracted data, and audit logs in an environment your team controls.

Private Cloud

Deploy inside your cloud account and use your existing identity, network, and monitoring controls.

On-Premises

Run the containerized services on infrastructure managed by your organization.

Zero Standing Access

Grant support access for an approved ticket and time window instead of leaving permanent vendor access enabled.

Deployment Models

Choose where the platform runs.

Deploy in your private cloud or on infrastructure you operate.

The platform runs as containerized services inside your environment. Your team can apply its existing identity, network, monitoring, and change-management policies.

Supplier documents, attachments, extracted data, findings, and audit logs remain within that deployment boundary.

Data Control

Apply the same controls to documents and results.

Protect the source files, extracted content, findings, and logs together.

A bid review contains more than uploaded files. It also creates extracted text, requirement grades, exclusions, reviewer notes, and audit records.

Your team controls where that data is stored, who can access it, and how activity is logged.

Support Model

Approve support access only when it is needed.

Support does not require permanent access to your environment.

Each support request identifies the ticket, the people who need access, and the approved time window.

This gives your team a clear record of who accessed the system, when they accessed it, and why.

Compliance Readiness

Review the deployment against your compliance requirements.

The platform supports your assessment; it does not make the deployment automatically compliant.

Private deployment, access controls, audit logs, and links to source evidence can support GDPR and EU AI Act assessments.

Your compliance position still depends on the configuration, operating policies, and use cases approved by your organization.

Identity and Auditability

Connect identity, roles, and audit logging.

Hosting location alone does not control access.

Define SSO integration, application roles, and audit logging before users begin reviewing bids.

Procurement, technical, and legal reviewers can then work in the same project with access appropriate to their responsibilities.

Review Inputs

Give security teams the material they need.

Review the software and its operating controls before deployment.

Security reviews may include the software bill of materials, penetration-test summaries, architecture details, and deployment guidance.

These materials help your team assess dependencies, system boundaries, and operating responsibilities.

Security Review

Start with deployment, access, and logging.

Confirm the basic control model before deeper technical review.

First confirm where the platform runs, who administers it, how support access works, and which actions are logged.

Procurement, legal, and security teams can then decide which additional technical checks are required.

Review the deployment with your security team.

We can walk through the architecture, access model, support process, and data boundaries.