Security

Last updated: September 2026  ·  TradeScope by Sajdak Group Holdings WLL

Your tender pack is commercially sensitive. Drawings, schedules, rates and margins are the things a competitor would most like to read. This page sets out plainly where that material goes and what protects it. Where a control isn't in place yet, it isn't listed here.

1. Where your data lives

Primary operational data is stored on AWS in Sydney (ap-southeast-2), within Australia. Tender documents are stored in isolated per-organisation buckets. Backups are encrypted and kept for disaster recovery only.

2. Encryption

Data is encrypted at rest and in transit. trade-scope.net, app.trade-scope.net and api.trade-scope.net all negotiate TLS 1.3; our Privacy Policy sets TLS 1.2 as the contractual floor. HTTP Strict Transport Security is set for one year with includeSubDomains and preload, so browsers refuse to talk to us over plain HTTP.

3. Browser-side hardening

Every page is served with a Content Security Policy that keeps scripts, styles, fonts and network calls on our own origins, plus:

You can check every one of these yourself: curl -I https://trade-scope.net

4. Your documents are not training data

Under our Terms you keep the intellectual property in your tender documents, scope data and estimates, and you grant us a licence to process them solely to provide the service. We don't train models on your tender documents, and we don't sell your data.

Scope extraction and RFI drafting send tender content to Anthropic's API for processing. Per Anthropic's API data retention policy, request content isn't retained beyond the processing call. Platform-improvement work uses aggregated, de-identified usage data only.

5. Who else touches it

These are the third parties in the path, each named in our Privacy Policy:

6. Access and sessions

Access to production data is restricted to platform administrators. Sign-in uses session cookies, and functional cookies remember preferences such as your last selected trade. No third-party advertising or tracking cookies.

7. Getting your data out, and deleting it

Under the Privacy Act 1988 (Cth) you can ask us to access or correct the personal information we hold, or to delete your account and its data. Account and tender data is kept while your subscription is active; after closure it's retained for seven years to meet financial and legal obligations under the Corporations Act 2001 and ATO requirements, then securely deleted. Requests go to our Privacy Officer — the contact and the 30-day response commitment are in the Privacy Policy.

8. Reporting a vulnerability

If you think you've found a security problem, email [email protected] with enough detail to reproduce it, and please give us a reasonable window to fix it before disclosing publicly. We don't run a paid bug bounty.

9. What we don't claim

We'd rather be straight with you than pad this page. TradeScope holds no third-party security certification and no independent security audit. We're a small Australian-operated team and the controls above are the ones we actually run. If your procurement process requires a certified provider, say so before you subscribe rather than after.

10. Contact

Security: [email protected]
Privacy: see the Privacy Policy
Website: trade-scope.net

← Back to TradeScope