Skip to content

Security

Your data is walled off per account

The tables that hold customer information — profiles, documents, certifications, proposals, tracked bids and billing — enforce row-level security in the database, scoping every row to the account that owns it.

Encryption

  • All traffic to the website, the app and our API is served over HTTPS.
  • The database and document storage are hosted with Supabase, which encrypts data at rest.

Sign-in

Sign-in is handled by Supabase Auth, by email or with your Google account. We never see or store your Google password. Every app page checks for a valid session before it loads.

Payments

Card details are entered with and held by Stripe. They never pass through or get stored on Bid Boots servers.

AI drafting

Proposals are drafted with Anthropic’s API. Only the parts of your profile, documents and the bid needed for a draft are sent, when you generate or revise one.

Access

Production credentials are held as deployment secrets rather than in source code, and access to production systems is limited to the people who operate the service.

Reporting a vulnerability

If you believe you have found a security issue, please email sales@bidboots.com with the details and steps to reproduce. Please give us a reasonable chance to fix it before disclosing it publicly, and don’t access or change other customers’ data while testing.

For what we collect and who processes it, see the Privacy Policy.