Security & privacy
This page describes controls that are implemented in the product today. It is not a certification statement — if your review needs formal attestations, questionnaires or a data-processing agreement, contact us and we will route the request to the right owner.
Access control
Ten built-in roles map to capability sets an administrator can edit. Two roles are department-scoped, so owners only write to their own records. External vendor users are restricted to the vendor portal.
Authentication
Email and password, Google sign-in, and optional app-based multi-factor authentication. SAML 2.0 / OIDC single sign-on can be configured with directory group to role mapping and just-in-time provisioning.
Document storage
Contract, vendor, intake, proposal and procurement files are held in private buckets. Downloads are served through short-lived signed links rather than public URLs.
Audit logging
Record writes, approvals, signature events, exports and connector activity are written to an audit log with actor, timestamp and change detail, readable on the record itself.
Retention & deletion
Retention policies can sweep expired records, legal holds block deletion while a matter is open, and deletion requests require a second approver before anything is removed.
AI handling
AI features run against documents you upload to produce proposals — extracted terms, drafts, summaries — that a person reviews before anything is saved. Nothing is written to a record without human approval.
Reporting a vulnerability
If you believe you have found a security issue, contact your account owner or the platform administrator for your organization with steps to reproduce. Please do not test against other tenants' data or run automated scans against production.
What we do not claim on this page
- No certification, audit outcome or regulatory compliance status is asserted here.
- No guarantee is made about the absence of vulnerabilities.
- Specific encryption, retention windows, subprocessors and hosting regions are confirmed in writing during your security review rather than stated here.