GTender
Sign in

Launch draft

Security and Responsible Disclosure

A customer-readable summary of implemented boundaries and a contact for good-faith security reports.

This document is prepared for founder and legal review. It is not effective, is not a legal promise, and must not be treated as final customer terms.

Status
Not effective. Human and legal approval required before customer launch.
Technical truth reviewed
24 August 2026
Proposed operator description
GTender, a product of Fashol. Exact legal entity name and registered address require founder confirmation.

1. Security approach

GTender treats company facts, documents, bid strategy, decisions, and work products as sensitive business data. Security controls are enforced at server and database boundaries and are not based only on hiding buttons in the interface.

2. Identity and sessions

The planned production authentication architecture uses Google Identity Platform with verified identity subjects, secure session cookies, expiry and revocation controls, non-enumerating sign-in errors, and server-side authorization. Organization invitation acceptance requires a short-lived token and a matching verified email identity.

3. Organization isolation

Organization-owned records use scoped server operations, PostgreSQL row-level security, restricted application roles, composite ownership relationships, and adversarial cross-tenant tests. Platform support roles do not automatically receive access to customer-private workspaces.

4. Documents

Private uploads use quarantine, file-type and size validation, antivirus scanning, private storage, bounded signed access, and provenance-preserving processing. Uploads are not sent to an external AI provider under the current approved configuration.

5. Infrastructure and providers

The planned production architecture separates production from staging, uses private PostgreSQL networking, Secret Manager, short-lived deployment identity, managed backups, deletion protection, and monitoring. Production deployment, restore proof, and final provider review remain launch gates.

6. Reporting a vulnerability

Please report suspected vulnerabilities privately with the affected URL, a concise reproduction, and possible impact. Do not access another customer's data, disrupt service, use destructive tests, or attack a third party. GTender does not yet promise a response time or bounty; both require an approved operating policy.

Questions, privacy requests, security reports, and policy concerns can currently be sent to sakib@fashol.com