Built for institutional trust.
The Connect serves governments, development banks, and regulated institutions. Security, compliance, and data governance are designed in from the ground up.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest. Secrets and keys are managed in the hosting platform's encrypted store, never in source.
Authentication & SSO
Email/password with secure session cookies, and enterprise SSO (SAML / OIDC) for institutional domains — sign in with your organization's identity provider. Two-factor authentication (TOTP) is available on all accounts.
Access control
PostgreSQL row-level security enforces that each account only reads its own data; platform intelligence is gated to authenticated subscribers. Admin and service-role operations are isolated from user sessions.
Tamper-evident audit trail
Every logged action is committed to a SHA-256 hash chain — each record links to the previous one, so any alteration, deletion, or reordering is cryptographically detectable and independently verifiable. The integrity of the trail can be recomputed on demand.
Sanctions & debarment screening
Bidders and their beneficial owners are screened against the OFAC SDN, UN Security Council, and UK OFSI consolidated lists. MDB cross-debarment (World Bank et al.) is available under a licensed feed. Coverage is stated exactly — a pending feed is never counted as screened.
Data residency & processing
Hosting and database run in managed, audited infrastructure. A Data Processing Agreement (DPA) is available for institutional customers; sub-processors are disclosed.
Open standards & portability
Procurement records export as a conformant Open Contracting Data Standard (OCDS 1.1) release package — machine-readable, portable, and ready for external integration and oversight.
Availability
The platform targets high availability with monitored ingestion and graceful degradation. Status and incident history are published for enterprise customers.