Security
Your credentials, your bids, your control
Bid documents are among the most sensitive files a company holds. Grovia Tender is built so that only your organisation can see them, every access is logged, and nothing leaves without a human decision.
Tenant isolation
Every record belongs to one organisation. Data access always goes through a tenant-scoped database client, and the isolation is covered by automated tests generated from the schema itself.
Encryption
TLS for everything in transit. Documents and database storage encrypted at rest. Provider keys and secrets stored encrypted, never in code.
Signed, short-lived URLs
Documents live in a private bucket. Every download and upload uses a short-lived signed URL issued only to an authenticated member of your organisation.
Role-based access
Owner, Admin, Bid Manager, Technical, Finance, Legal and Viewer roles with a capability matrix. Invite people to see only what they need.
Audit logs
Who did what, when, from where, for every sensitive action: logins, document access, approvals, role changes, exports.
Malware scanning and limits
Uploads are scanned, rate limits guard the API, and sessions can be protected with multi-factor authentication.
No automatic submission
There is no code path that submits a bid, signs a document or approves pricing. The final package is built only after your explicit approval.
Your data is never used for training
Your documents, bids and outcomes are private to your organisation. They are not used to train AI models and are never shown to other customers.
Auditable AI
Every AI call is metered, logged and linked to the output it produced. Outputs that cannot be verified against a document are flagged for review, never stored as fact.
Data handling
Where your data lives and how it moves
- Hosting
- Grovia Tender runs on Webzworld infrastructure with its own database, storage bucket and processes, independent of every other Webzworld product. Data is stored in the Asia-Pacific (Mumbai) region.
- Tender sources
- Official APIs, licensed feeds, and documents you upload. We do not scrape government portals or bypass logins, CAPTCHAs or signatures.
- AI providers
- Documents are sent to AI providers only to perform the analysis you request, over encrypted connections, under terms that prohibit training on your data. Enterprise customers can opt for a private AI deployment.
- Retention and export
- Your data stays for as long as your account exists. You can export your documents and bids at any time and request deletion of the organisation.
- Backups
- Encrypted daily backups of the database and storage, restorable per product.
- Reporting an issue
- Email hello@groviatender.com with “security” in the subject line. We acknowledge within two business days.
Formal certifications (for example ISO 27001) are not claimed at this time. This page will be updated as third-party assessments are completed.
Want the details before you upload anything?
We are happy to walk your IT or legal team through the architecture.