Security
Connecting a tender portal means trusting us with a login, so this page sets out plainly how we protect your data — especially the portal credentials you may connect — and how to report a security issue.
Last updated: 30 June 2026
Portal credentials are encrypted
When you connect a tender portal, your credentials are encrypted before they’re stored. They are decrypted only inside the secured background jobs that log in to fetch your tenders on your behalf — never in your browser, never returned to the front end, and never exposed to other users. Disconnecting a portal removes that access.
Encryption in transit and at rest
All traffic to TenderWatch is served over HTTPS/TLS. Your data is stored in a managed PostgreSQL database (Supabase) with encryption at rest, and connected-portal credentials carry the additional application-level encryption described above.
Isolation between accounts
Data access is enforced at the database with row-level security, so your records are scoped to your account and not reachable by other users. Background browsers that fetch tenders run in isolated, short-lived sessions.
Payments
Subscription payments are handled by Stripe. Card details go directly to Stripe and are not stored on our servers.
Trusted infrastructure
We build on established providers — Supabase, Vercel, Stripe, Anthropic, Browserbase and Resend — and apply least-privilege access to the keys and services we operate. Errors are monitored so we can respond to problems quickly.
Your part
Use a strong, unique password, keep it private, and disconnect any portal you no longer want us to access. Tell us straight away if you think your account has been compromised.
Reporting a vulnerability
If you believe you’ve found a security issue, please email dennis@corporateaisolutions.com (or use our Contact page) before disclosing it publicly, and give us a reasonable chance to fix it. We appreciate responsible disclosure.