Sign in Get started

Security & Data Handling

We understand that RFPs and proposal documents contain sensitive business information. Here is exactly how BidBaseline handles your data.

At a Glance

Your documents are stored in private, isolated storage buckets.

Your data is not used to train any AI models.

Your data is not sold or shared with third parties.

All access is authenticated and scoped to your account.

Document downloads use short-lived signed URLs.

You can delete your projects and all associated data at any time.

Document Storage

Uploaded RFP files are stored in private storage buckets accessible only by the application backend. Files are associated with your account and are not accessible by other users.

When you export a compliance matrix, the generated file is stored temporarily and accessed via a short-lived signed URL that expires after a limited time.

Data Processing

Your documents are processed to extract requirements, deliverables, and evaluation criteria. This processing involves document parsing and AI-assisted extraction to produce structured outputs.

Third-party processing services are used only to provide the core service (document parsing and text analysis). We configure these services for minimal data retention where supported.

Your Data, Your Control

We do not use your uploaded documents, extracted requirements, or compliance matrix data to train any public or private AI models.

We do not sell, license, or share your data with any third party for purposes other than providing the BidBaseline service.

When you delete a project, all associated data is permanently removed — including the uploaded document, parsed content, extracted requirements, and generated exports.

Authentication & Access

All API requests are authenticated using industry-standard JWT tokens. Backend access to storage and database is restricted to service-level credentials that are never exposed to the client.

Each user's data is isolated at the application level. You can only access projects that belong to your account.

Infrastructure

BidBaseline runs on dedicated infrastructure hosted in secure data centers. The database, storage, and application services operate within private networks with restricted access.

Questions?

If you have specific security requirements or questions about data handling, reach out to us at security@bidbaseline.com. We are happy to discuss your compliance needs.

Last updated: February 2026