Security and trust
Government contractors trust us with their pipeline. Here is how we look after it.
Modern sign-in
Accounts sign in through WorkOS AuthKit with a one-time email code, a passkey, or your company's single sign-on. We never see or store a password.
Roles and sign-in policies
Everyone on your team is an Owner, Admin, Member or Viewer. Owners can require multi-factor sign-in for the whole team and, on plans that include them, single sign-on and directory sync (SCIM).
A team audit log
Owners and admins can view and export a log of security-relevant actions, such as invitations, role changes, API keys and exports.
Encrypted in transit and at rest
All traffic uses TLS. The application runs on Cloudflare, whose databases and object storage encrypt data at rest with AES-256-GCM.
Only the data we need
The solicitations we collect are public records. For your account we keep what sign-in and your team's settings need, as the privacy policy describes.
A strict browser policy
Our pages send a strict Content Security Policy. This site runs no JavaScript at all by default, loads no third-party trackers and hosts its own fonts.