Skip to content
Grovia Tender

Security

Your credentials, your bids, your control

Bid documents are among the most sensitive files a company holds. Grovia Tender is built so that only your organisation can see them, every access is logged, and nothing leaves without a human decision.

Tenant isolation

Every record belongs to one organisation. Data access always goes through a tenant-scoped database client, and the isolation is covered by automated tests generated from the schema itself.

Encryption

TLS for everything in transit. Documents and database storage encrypted at rest. Provider keys and secrets stored encrypted, never in code.

Signed, short-lived URLs

Documents live in a private bucket. Every download and upload uses a short-lived signed URL issued only to an authenticated member of your organisation.

Role-based access

Owner, Admin, Bid Manager, Technical, Finance, Legal and Viewer roles with a capability matrix. Invite people to see only what they need.

Audit logs

Who did what, when, from where, for every sensitive action: logins, document access, approvals, role changes, exports.

Malware scanning and limits

Uploads are scanned, rate limits guard the API, and sessions can be protected with multi-factor authentication.

No automatic submission

There is no code path that submits a bid, signs a document or approves pricing. The final package is built only after your explicit approval.

Your data is never used for training

Your documents, bids and outcomes are private to your organisation. They are not used to train AI models and are never shown to other customers.

Auditable AI

Every AI call is metered, logged and linked to the output it produced. Outputs that cannot be verified against a document are flagged for review, never stored as fact.

Data handling

Where your data lives and how it moves

Hosting
Grovia Tender runs on Webzworld infrastructure with its own database, storage bucket and processes, independent of every other Webzworld product. Data is stored in the Asia-Pacific (Mumbai) region.
Tender sources
Official APIs, licensed feeds, and documents you upload. We do not scrape government portals or bypass logins, CAPTCHAs or signatures.
AI providers
Documents are sent to AI providers only to perform the analysis you request, over encrypted connections, under terms that prohibit training on your data. Enterprise customers can opt for a private AI deployment.
Retention and export
Your data stays for as long as your account exists. You can export your documents and bids at any time and request deletion of the organisation.
Backups
Encrypted daily backups of the database and storage, restorable per product.
Reporting an issue
Email hello@groviatender.com with “security” in the subject line. We acknowledge within two business days.

Formal certifications (for example ISO 27001) are not claimed at this time. This page will be updated as third-party assessments are completed.

Want the details before you upload anything?

We are happy to walk your IT or legal team through the architecture.