Launch draft
Security and Responsible Disclosure
A customer-readable summary of implemented boundaries and a contact for good-faith security reports.
This document is prepared for founder and legal review. It is not effective, is not a legal promise, and must not be treated as final customer terms.
- Status
- Not effective. Human and legal approval required before customer launch.
- Technical truth reviewed
- 24 August 2026
- Proposed operator description
- GTender, a product of Fashol. Exact legal entity name and registered address require founder confirmation.
1. Security approach
GTender treats company facts, documents, bid strategy, decisions, and work products as sensitive business data. Security controls are enforced at server and database boundaries and are not based only on hiding buttons in the interface.
2. Identity and sessions
The planned production authentication architecture uses Google Identity Platform with verified identity subjects, secure session cookies, expiry and revocation controls, non-enumerating sign-in errors, and server-side authorization. Organization invitation acceptance requires a short-lived token and a matching verified email identity.
3. Organization isolation
Organization-owned records use scoped server operations, PostgreSQL row-level security, restricted application roles, composite ownership relationships, and adversarial cross-tenant tests. Platform support roles do not automatically receive access to customer-private workspaces.
4. Documents
Private uploads use quarantine, file-type and size validation, antivirus scanning, private storage, bounded signed access, and provenance-preserving processing. Uploads are not sent to an external AI provider under the current approved configuration.
5. Infrastructure and providers
The planned production architecture separates production from staging, uses private PostgreSQL networking, Secret Manager, short-lived deployment identity, managed backups, deletion protection, and monitoring. Production deployment, restore proof, and final provider review remain launch gates.
6. Reporting a vulnerability
Please report suspected vulnerabilities privately with the affected URL, a concise reproduction, and possible impact. Do not access another customer's data, disrupt service, use destructive tests, or attack a third party. GTender does not yet promise a response time or bounty; both require an approved operating policy.
Contact
Questions, privacy requests, security reports, and policy concerns can currently be sent to sakib@fashol.com