Trust Centre

Security, privacy and data handling

How TenderHive Intelligence protects your data, keeps the platform available, and handles privacy and security requests.

A transparent view of how the platform is built, operated and protected. The controls below are active in production today. If you need a data-processing agreement, subprocessor list or security questionnaire, use the form at the bottom of the page — we respond within one business day.

Access control

  • Accounts sign in with email and password or Google, with optional time-based two-factor authentication.
  • Workspace owners and admins can require two-factor authentication for administrative actions in their organisation.
  • Roles are owner, admin, member and viewer; platform staff roles are held separately from customer workspaces.
  • Every permission is enforced on the server; the interface never decides access on its own.

Tenant isolation

  • Customer records are scoped to an organisation and enforced by row-level database policies keyed to the signed-in user.
  • API keys are stored only as hashes; the full value is shown once at creation and never again.
  • Sensitive workspace actions are written to an append-only organisation audit trail that cannot be edited or deleted.

Availability and recovery

  • Managed Postgres with point-in-time recovery on the primary database.
  • A daily encrypted logical backup of business-critical tables is written to independent storage, with keys held outside the backup location.
  • Restore drills are performed into an isolated environment using synthetic data.
  • Current operating state is published on the status page.

Data handling and retention

  • Tender notices are collected from published public and buyer sources and retained as a searchable archive.
  • Customer workspace data (members, saved searches, pipeline, usage) is retained while the account is active and removed on request.
  • Exports are organisation-scoped, server-authorised and recorded in the audit trail.

Subprocessors

TenderHive Intelligence uses third parties for application hosting and databases, transactional email delivery, payment processing and AI evaluation features. A current, named subprocessor list is provided on request through the form below or with a data processing agreement.

Privacy rights

You can request access to, correction of, export of or deletion of your personal and organisation data. See our privacy notice and terms. Live service state is published on the status page.

Reporting a vulnerability

Report suspected vulnerabilities privately using the form below, or email support@tenderhive.com. Please do not test against other customers' data.

Make a request

Sign in to raise a tracked request, or email support@tenderhive.com.