Security Measures
Version 1.0 · Effective 2026-09-25
This document describes the technical and organisational measures (TOMs) that ACCER INFORMATION TECHNOLOGY LIMITED, trading as Tender Preflight, applies to the Tender Preflight service. It forms Annex 2 of the Data Processing Agreement and is our description of security under Article 32 GDPR. Report a vulnerability or a suspected incident to [email protected].
1. Controls built into the software
Tenant isolation
- Every record belongs to one customer organisation.
- Every database query is limited to the signed-in organisation.
- Stored files are kept per organisation.
- Requests for another organisation's data are answered as "not found". Automated tests check this for every page.
Authentication and sessions
- Passwords must be at least 10 characters. They are stored only as salted Argon2 hashes.
- Session cookies are signed, HTTP-only and
SameSite=Lax, and they expire after 14 days. - Every form that changes data carries an anti-CSRF token.
Web hardening
- Pages are served with
X-Content-Type-Options: nosniff,X-Frame-Options: DENYand a same-origin referrer policy. - No third-party scripts, fonts or trackers are loaded.
Upload safety
- The real file type is detected from the file's content, not only from its extension.
- The size of each file is limited to 100 MB.
- Archives are unpacked with protection against path traversal and "zip bombs".
- Unsafe or unreadable files are marked as not checked, never silently processed.
- Documents are parsed and never executed. Spreadsheet formulas are evaluated by our own evaluator, not by office software.
AI processing
- The language model runs on our own infrastructure in Ireland (European Union). No Customer Content is sent to external AI services.- Only extracted text passages are submitted to the model, never the files themselves.
- Model output is used as data, never as instructions: citations are checked against the source text, and severity is decided by fixed rules.
- Customer Content is never used for training.
Minimisation and logging
- Prompts and document text are not written to application logs.- Cached model responses are linked to their tender and deleted with it.
Retention and deletion
- Customers can delete documents, tenders or their account at any time. Deletion removes the files and everything derived from them.
- Tenders that have not been checked for 90 days are deleted automatically, by a job that runs every day.
Integrity and traceability
- Every uploaded file is identified by its SHA-256 fingerprint.
- Decisions on findings are recorded in an audit trail with the account and the reason.
- Acceptance of the legal documents is recorded against the SHA-256 of the exact text.
2. Operational measures
Hosting
- The Service runs on servers operated by ACCER INFORMATION TECHNOLOGY LIMITED in Ireland (European Union).
- The server is reached only through Cloudflare (Cloudflare Tunnel): the server makes an outbound-only connection to Cloudflare, so it has no open inbound port and its network address is not publicly known. Cloudflare's edge also provides DDoS and bot protection in front of the Service. See the Sub-processor List and DPA §9 for what this means for the location of processing.
- Access to production systems is limited to named administrators, and requires personal accounts and SSH keys or multi-factor authentication.
Encryption
- Traffic to the Service is encrypted with TLS 1.2 or higher.
- Storage volumes and backups are encrypted at rest.
Backups
- Backups are encrypted, access-restricted and kept for no more than 35 days.
- Restores are tested periodically.
Patching
- Operating system and dependency security updates are applied according to severity.
- Critical vulnerabilities are addressed as a priority.
Logs
- Server and security logs are kept for 30 days, with restricted access.
Personnel
- Everyone with access to customer data is bound by confidentiality.
- Access is granted on a need-to-know basis and removed when it is no longer required.
Incident response
- Suspected incidents are triaged, contained and documented.
- Customers are notified of personal data breaches within 48 hours of our becoming aware (DPA section 11).
Supplier management
- Sub-processors are engaged only under written data processing terms (DPA section 8).
Review
- These measures are reviewed at least once a year and after any significant change or incident.
3. Customer responsibilities
Customers are responsible for:
- choosing strong passwords and not sharing accounts;
- uploading only the personal data needed for a check;
- deleting tenders they no longer need; and
- reviewing findings before relying on them.