Built for institutional trust.
The Connect serves governments, development banks, and regulated institutions. Security, compliance, and data governance are designed in from the ground up.
Encryption
All data is encrypted in transit (TLS 1.2+) and at rest. Secrets and keys are managed in the hosting platform's encrypted store, never in source.
Authentication
Email/password and SSO-ready authentication with secure session cookies. Two-factor authentication (TOTP) is available for all accounts and recommended for institutional users.
Access control
Row-level security enforces that users only access their own account data; platform intelligence is gated to authenticated subscribers. Admin and service operations are isolated.
Data residency & processing
Hosting and database run in managed, audited infrastructure. A Data Processing Agreement (DPA) is available for institutional customers; sub-processors are disclosed.
Sanctions & compliance screening
Bidders and entities are screened against OFAC, EU, and UN consolidated lists. Source attribution and confidence scoring support compliance review.
Availability
The platform targets high availability with monitored ingestion and graceful degradation. Status and incident history are published for enterprise customers.