Tender Pilot KE

Security & Compliance

Implemented website safeguards, planned product controls and an accurate view of current compliance status.

01

ODPC Registration — In Progress

Tender Pilot’s ODPC registration is currently in progress. We do not claim to be ODPC registered, certified or approved. This page will be updated when the status can be verified.

02

Current design approach

The product is being designed around data minimization, defined integration boundaries and server-side handling of private service credentials. The waitlist uses Zoho CRM’s public web-to-lead form identifiers; no private Zoho API key is shipped in the browser bundle.

03

Access control

Production access roles, authentication controls and internal access procedures are still being finalized.

04

Tender and business information

Tender and company information should be collected only for stated workflows, restricted to authorized access and removed under an approved retention process. Users should avoid submitting unnecessary personal or sensitive information.

05

Secure development

The development approach includes type checking, dependency review, server-side secret management and scoped external integrations. This is a statement of current engineering practice, not a certification or independent audit.

06

Third-party services

The marketing site uses Vercel for hosting, analytics and performance insights, and Zoho CRM for waitlist subscriptions.

07

Planned work

Before general availability, Tender Pilot should approve incident handling, retention, access reviews, user request procedures, vendor management and data-protection documentation. Planned work is not represented as already implemented.

08

Report a concern

Email us on: support@tenderpilot.co. Do not include sensitive details in an ordinary support message until a secure reporting route is confirmed.