You work in a market trained to ask hard security questions. Here are straight answers — including what BidStrike is not built to handle.
BidStrike operates on pre-award, publicly available information — solicitations and notices from SAM.gov and other public portals, public award data, and the company profile and proposal drafts you create in the platform.
BidStrike is not a CUI system. It is not authorized to store or process Controlled Unclassified Information, classified material, or ITAR-controlled technical data. If your contract work involves CUI, keep that material in your compliant environment — BidStrike handles the pre-award pursuit, not controlled deliverables. We state this plainly because implying otherwise is how contractors get hurt.
All traffic is encrypted in transit (TLS 1.2+). Data is encrypted at rest by our infrastructure providers. Company documents live in private storage buckets, never public URLs.
Every agency and every client workspace is isolated. Queries are scoped per tenant; one customer's proposals, pipeline, and profile are never visible to another.
Authentication is handled by Clerk, a dedicated identity provider. Role-based access with per-user, per-section permissions; admin actions are restricted server-side, not just hidden in the UI.
Our AI assistants operate through a locked-down set of permission-checked operations. Destructive or outward-facing actions require your explicit approval, and every AI action is written to an audit log.
Your proposals and profile are sent to our AI provider (Anthropic) solely to generate your drafts, briefs, and reviews. We do not sell your data, and we do not use your proposals to build products for other customers. Your drafts are yours.
Submissions, plan changes, webhook events, and AI actions are logged with actor and timestamp. If something happened in your account, there's a record of who did it and when.
We build on established infrastructure rather than running our own servers. Current subprocessors:
| Provider | Purpose |
|---|---|
| Vercel | Application hosting and delivery |
| Supabase | Database and file storage (encrypted at rest) |
| Clerk | Authentication and identity |
| Anthropic | AI drafting, analysis, and review |
| Stripe | Payment processing (we never store card numbers) |
| Resend | Transactional email delivery |
| Svix | Outbound webhook delivery for agency integrations |
BidStrike does not currently hold SOC 2, CMMC, or FedRAMP certification, and we won't imply otherwise with lookalike badges. Those frameworks exist for systems that handle controlled government data — which, per the boundary above, BidStrike deliberately does not.
What we do instead: the practices on this page, enforced in code, on infrastructure providers who carry their own extensive compliance programs. As BidStrike grows up-market, formal certification (starting with SOC 2) is on our roadmap — and this page will say so plainly when it's underway, not before.
Security questions, disclosures, or a vulnerability to report: contact us.
Ask directly — you'll get a straight answer from the team that built it.
Contact Us