# Security Measures

**Version 1.0** · Effective 2026-09-25

This document describes the technical and organisational measures (**TOMs**) that **ACCER INFORMATION TECHNOLOGY LIMITED**, trading as
**Tender Preflight**, applies to the Tender Preflight service. It forms Annex 2 of the [Data Processing Agreement](/dpa) and is our description of security under
Article 32 GDPR. Report a vulnerability or a suspected incident to **contact@accer.top**.

## 1. Controls built into the software

**Tenant isolation**

- Every record belongs to one customer organisation.
- Every database query is limited to the signed-in organisation.
- Stored files are kept per organisation.
- Requests for another organisation's data are answered as "not found". Automated tests check this for every page.

**Authentication and sessions**

- Passwords must be at least 10 characters. They are stored only as salted **Argon2** hashes.
- Session cookies are signed, HTTP-only and `SameSite=Lax`, and they expire after 14 days.
- Every form that changes data carries an anti-CSRF token.

**Web hardening**

- Pages are served with `X-Content-Type-Options: nosniff`, `X-Frame-Options: DENY` and a same-origin referrer policy.
- No third-party scripts, fonts or trackers are loaded.

**Upload safety**

- The real file type is detected from the file's content, not only from its extension.
- The size of each file is limited to 100 MB.
- Archives are unpacked with protection against path traversal and "zip bombs".
- Unsafe or unreadable files are marked as not checked, never silently processed.
- Documents are parsed and never executed. Spreadsheet formulas are evaluated by our own evaluator, not by office
  software.

**AI processing**

- The language model runs on our own infrastructure in Ireland (European Union). No Customer
  Content is sent to external AI services.- Only extracted text passages are submitted to the model, never the files themselves.
- Model output is used as data, never as instructions: citations are checked against the source text, and severity
  is decided by fixed rules.
- Customer Content is never used for training.

**Minimisation and logging**

- Prompts
  and document text are not written to application logs.- Cached model responses are linked to their tender and deleted with it.

**Retention and deletion**

- Customers can delete documents, tenders or their account at any time. Deletion removes the files and everything
  derived from them.
- Tenders that have not been checked for 90 days are deleted automatically, by a job that runs
  every day.

**Integrity and traceability**

- Every uploaded file is identified by its SHA-256 fingerprint.
- Decisions on findings are recorded in an audit trail with the account and the reason.
- Acceptance of the legal documents is recorded against the SHA-256 of the exact text.

## 2. Operational measures

**Hosting**

- The Service runs on servers operated by ACCER INFORMATION TECHNOLOGY LIMITED in Ireland (European Union).
- The server is reached only through Cloudflare (Cloudflare Tunnel): the server makes an outbound-only connection to
  Cloudflare, so it has no open inbound port and its network address is not publicly known. Cloudflare's edge also
  provides DDoS and bot protection in front of the Service. See the [Sub-processor List](/subprocessors) and DPA
  §9 for what this means for the location of processing.
- Access to production systems is limited to named administrators, and requires personal accounts and SSH keys or
  multi-factor authentication.

**Encryption**

- Traffic to the Service is encrypted with TLS 1.2 or higher.
- Storage volumes and backups are encrypted at rest.

**Backups**

- Backups are encrypted, access-restricted and kept for no more than 35 days.
- Restores are tested periodically.

**Patching**

- Operating system and dependency security updates are applied according to severity.
- Critical vulnerabilities are addressed as a priority.

**Logs**

- Server and security logs are kept for 30 days, with restricted access.

**Personnel**

- Everyone with access to customer data is bound by confidentiality.
- Access is granted on a need-to-know basis and removed when it is no longer required.

**Incident response**

- Suspected incidents are triaged, contained and documented.
- Customers are notified of personal data breaches within 48 hours of our becoming aware
  (DPA section 11).

**Supplier management**

- Sub-processors are engaged only under written data processing terms (DPA section 8).

**Review**

- These measures are reviewed at least once a year and after any significant change or incident.

## 3. Customer responsibilities

Customers are responsible for:

- choosing strong passwords and not sharing accounts;
- uploading only the personal data needed for a check;
- deleting tenders they no longer need; and
- reviewing findings before relying on them.
