Skip to content
BidLayersBidLayers | controlled bid operations
Security & trust

How we handle your tender data.

This page is maintained by the BidLayers team to answer common security and privacy questions about the platform. It describes controls that are enabled today and how responsibility is shared between BidLayers, the model providers you choose and your own organisation. It is not an independent certification.

Enabled controls

What the platform enforces today.

Tenant isolation

Per-workspace data boundary. Enterprise deployments add per-tenant encryption keys and optional VPC or on-premise hosting.

Access & identity

SSO via Okta, Microsoft Entra ID and Ping. SCIM provisioning, group-based roles, IP allow-listing and session policies.

Model routing

Prompts and responses transit directly between your tenant and the model endpoint under your own provider contract. BidLayers does not retain model inputs or outputs beyond what your workspace policy stores.

Audit trail

Every skill run, approval action and export is logged with actor, timestamp and source lineage. Signed submission archives at every tender close.

Data lifecycle

Configurable retention per workspace. Purge on demand. Deletion propagates to derived indices within the documented SLA.

Human governance

Approval levels (Auto, Reviewer, Approver) are enforced by the platform. No client-facing artefact leaves the system without a named signature.

Shared responsibility

Three parties, one governed workflow.

Party 01
BidLayers

Runs the orchestration platform, enforces approval levels, records the audit trail, isolates tenants, ships security updates and operates the workspace infrastructure.

Party 02
Model provider

You choose the model, Anthropic, OpenAI, Google, Azure, Bedrock, Mistral or self-hosted. The provider governs inference under the contract you sign with them, including data residency and retention.

Party 03
Your organisation

Owns the tender data, the knowledge library, the approval graph, user provisioning, retention policy and any regulatory obligations attaching to your bids.

Compliance posture

Where we are on the certification roadmap.

BidLayers is engineered to the ISO 27001 and SOC 2 control set. Independent attestation is in progress; we will publish certificates and audit letters here as they are issued. Ask us for the current control-mapping document under NDA.

Report a vulnerability

Coordinated disclosure.

We welcome reports from security researchers. Email security@bidlayers.com with details and, if possible, a reproducible test case. We acknowledge within two business days.

Contact the team →