Security.

Last updated: 2026-09-14

This page describes how BidFit handles your data, what we store, who processes it on our behalf, and how we communicate when something goes wrong. It's written for procurement officers, IT leads, and anyone evaluating BidFit before paste a tender URL.

What we store

We do not store full attachment files (RFP PDFs, addenda) — only notice metadata extracted from public listing pages.

Encryption

Authentication

BidFit uses passwordless sign-in. You request a sign-in link by email; each link is single-use and expires after 7 days. Signing in sets a session cookie marked HttpOnly, Secure, and SameSite=Lax, and signing out deletes the session on our side as well as in your browser. We do not store passwords. Your first brief does not require an account.

Third-party processors

BidFit is a small operation that relies on a short list of vetted vendors:

VendorPurposeData shared
Vercel (US East)Hosting + serverless compute + edge cacheAll site traffic, request logs
AnthropicClaude API for tender scoringTender notice text + your company profile (per request, not retained for training)
Google (Analytics, Tag Manager)Site analyticsAggregated event data, no PII
Meta (Pixel)Retargeting pool buildingPage views, anonymized event triggers
Upstash (Redis)Profiles, saved tenders, briefs, sessionsCompany profile, email, saved tenders, generated briefs
ResendTransactional emailEmail address, sign-in links, brief and billing emails
StripeSubscription billingEmail, plan, billing details (card data is handled by Stripe and never reaches BidFit servers)
FirecrawlReading provincial portal listingsPublic tender page URLs only

Anthropic's API does not use customer inputs to train models (per their commercial terms). Payments are processed by Stripe; BidFit never sees or stores your full card number.

Breach notification

If we discover a security incident affecting customer data, we will notify affected users by email within 72 hours of confirming the scope. We will publish a public post-mortem within 14 days describing what happened, what data was involved, and what we changed to prevent recurrence. This commitment exceeds PIPEDA's "as soon as feasible" requirement.

Vulnerability reporting

If you find a security vulnerability, please email us before disclosing publicly. We will acknowledge receipt within 24 hours and provide a fix timeline within 7 days. We don't operate a paid bounty program yet, but we publicly thank reporters who find substantive issues (with permission).

Security contact
security@bidfit.ca