Secure RFP Software for Confidential Tenders
Your tender documents are company-confidential data, and a tender pack usually arrives with confidentiality obligations attached before you have decided whether to bid. Secure RFP software has to be built around that constraint rather than apologise for it afterwards.
The free analyzer never uploads anything
The ordinary free-tool bargain is that you send your document to a stranger's server in exchange for a result. For a confidential procurement pack, that is a bad trade — and it is the reason most bid teams cannot try tools on live work.
So the analyzer does not make that trade. Parsing, clause detection, date extraction and counting all run in JavaScript on your machine. There is no request carrying your document anywhere, and you can confirm that in your browser's network tab in about ten seconds.
The practical consequence: you can evaluate the tool on a live confidential tender today, without a data processing agreement, a security questionnaire or a procurement conversation first.
What we do not claim
There is no SOC 2 badge, no ISO 27001 badge and no compliance seal anywhere on this site. None has been achieved yet, and advertising one before the audit completes would be precisely the unsupported claim this product is designed to prevent in your proposals.
Implemented controls in the paid platform
This list describes what the platform does, not what it aspires to. Future capabilities are named as future.
Documents as untrusted input
A tender document is written by someone outside your organisation, and a company document may have passed through many hands. Either can contain text aimed at an AI system — "ignore previous instructions" and its many variations.
Every extraction and generation prompt therefore states that uploaded document text is data, never instruction, and that no content inside a document may alter system behaviour. The same rule applies to Company Brain material, which is sanitised and isolated on the same basis.
Analytics that carry no content
Product analytics record that an analysis completed, that a response was generated, that an export ran. They never carry tender text, requirement content, proposal responses, company documents or filenames that could disclose a confidential opportunity.
Error logging follows the same rule: payloads are redacted, and confidential document content is not written to logs in order to make debugging easier.
Security questions
Is TenderOS SOC 2 or ISO 27001 certified?
Does the free analyzer send my document anywhere?
Are our documents used to train AI models?
Where is our data stored?
What happens when we delete something?
How long is data retained?
Can an administrator read our tender documents?
Enterprise security review, data processing terms or a completed vendor questionnaire? Talk to us — and if you are on the other side of that process, our guide to security questionnaire automation may be useful.