Your bids are your business. Here’s exactly how we keep them that way.
Government bidding means handing over your pricing, your people and your track record. You should know where that goes. No vague assurances — here’s the actual architecture.
Your data is stored and hosted in Sydney.
The TenderScout database and document storage run in AWS ap-southeast-2 (Sydney). The application is deployed to Vercel’s Sydney region. Your account, your business profile, the tender documents you upload, your requirements matrices and your drafts all live on Australian soil. We migrated off Singapore to Sydney in July 2026 specifically so this sentence could be true.
One firm never sees another’s work on the same tender.
Every table that holds your data enforces row-level security in the database itself, not in application code. A query for another organisation’s rows doesn’t return an empty list — it is refused at the database. Your requirements matrix, drafts, notes, library documents and pipeline are isolated per account, and per business profile within your account. Two firms can be bidding the same RFT on TenderScout right now and neither can tell.
You download tender documents yourself and decide what goes in.
Scout doesn’t hoover portals for attachments behind your login or hold credentials to government systems. You upload the RFT and addenda you want analysed. Nothing else is read. That’s a privacy decision, not a limitation.
We use compliant frontier models, under enterprise terms, and your work is never training data.
TenderScout runs on frontier AI models from established US and European providers, under commercial terms that prohibit training on customer content. We do not use models from providers restricted for Australian government use. Your documents, drafts and business profile are never used to train a model — ours or anyone else’s. We don’t sell your data, we don’t advertise against it, and we don’t pool it across customers. Model providers are listed by name in our Privacy Policy.
Encrypted in transit and at rest.
Every connection to TenderScout is TLS-encrypted. Data at rest — database and uploaded documents — is encrypted with AES-256 by our infrastructure provider. Passwords are hashed, never stored in readable form, and we never see them.
We never see your card.
Billing runs through Stripe. Card details go to Stripe directly and are never transmitted to or stored on TenderScout servers. We hold a customer reference and your plan status — nothing more.
Your data leaves when you do.
We keep your information while your account is active. Ask us to delete it and we delete it — account, profile, documents, drafts. Email support@tenderscout.au and we’ll confirm in writing when it’s done.
We’re not certified, and we’re not going to imply we are.
TenderScout is a young Australian product. We don’t hold ISO 27001 or SOC 2 — those cost more than a pre-revenue company has, and claiming otherwise would be exactly the kind of thing this page exists to avoid. What we have is the architecture above, and a policy of telling you the truth about it. If your procurement process needs something specific, ask and we’ll answer straight.
Questions we haven’t answered? Email support@tenderscout.au. A real person in Melbourne reads it.