Security & Trust

No borrowed badges.
Just how it actually works.

You work in a market trained to ask hard security questions. Here are straight answers — including what BidStrike is not built to handle.

The data boundary — read this first

BidStrike operates on pre-award, publicly available information — solicitations and notices from SAM.gov and other public portals, public award data, and the company profile and proposal drafts you create in the platform.

BidStrike is not a CUI system. It is not authorized to store or process Controlled Unclassified Information, classified material, or ITAR-controlled technical data. If your contract work involves CUI, keep that material in your compliant environment — BidStrike handles the pre-award pursuit, not controlled deliverables. We state this plainly because implying otherwise is how contractors get hurt.

Practices

How your data is protected

Encryption

All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest by our infrastructure providers. Company documents live in private storage buckets, never public URLs.

Tenant isolation

Every agency and every client workspace is isolated. Queries are scoped per tenant; one customer's proposals, pipeline, and profile are never visible to another.

Authentication & access

Authentication is handled by Clerk, a dedicated identity provider. Role-based access with per-user, per-section permissions; admin actions are restricted server-side, not just hidden in the UI.

AI with guardrails

Our AI assistants operate through a locked-down set of permission-checked operations. Destructive or outward-facing actions require your explicit approval, and every AI action is written to an audit log.

Your data and AI models

Your proposals and profile are sent to our AI provider (Anthropic) solely to generate your drafts, briefs, and reviews. We do not sell your data, and we do not use your proposals to build products for other customers. Your drafts are yours.

Auditability

Submissions, plan changes, webhook events, and AI actions are logged with actor and timestamp. If something happened in your account, there's a record of who did it and when.

Subprocessors

Who touches your data

We build on established infrastructure rather than running our own servers. Current subprocessors:

ProviderPurpose
VercelApplication hosting and delivery
SupabaseDatabase and file storage (encrypted at rest)
ClerkAuthentication and identity
AnthropicAI drafting, analysis, and review
StripePayment processing (we never store card numbers)
ResendTransactional email delivery
SvixOutbound webhook delivery for agency integrations
Certifications

Where we stand — honestly

Questions we didn't answer?

Ask directly — you'll get a straight answer from the team that built it.

Contact Us