Security at GovDemand

Security built into the platform.

GovDemand is designed to protect supplier information, procurement data and platform operations through layered technical and organizational safeguards.

Security is incorporated into how we design, build and operate the platform — from authentication and database access to infrastructure, monitoring and data handling.

GovDemand has not currently undergone a SOC 2 examination or received SOC 2 attestation. Our security program is being developed with reference to recognized industry security practices and frameworks.

Our security approach

Security by design.

GovDemand uses a defense-in-depth approach intended to reduce risk across the application, infrastructure, data and user-access layers. Our practices are informed by established security frameworks, including the principles underlying SOC 2.

Encryption

Data is encrypted in transit using TLS/HTTPS and protected at rest using the security capabilities of our infrastructure providers.

Access control

Authentication, authorization and role-based access controls restrict access to platform functionality and data.

Database security

Row Level Security and scoped database permissions are designed so users can access only the information they are authorized to access.

Secrets management

API credentials, database credentials and other sensitive secrets remain server-side and are never exposed through client-side code.

Secure application architecture

External data integrations run through controlled server-side services rather than exposing privileged credentials or infrastructure to browsers.

Logging & monitoring

We maintain operational logging for critical integrations, and are expanding security and administrative activity logging as the platform grows.

Least-privilege access

Administrative and system access is limited to what is necessary for each role or service.

Secure development

Security is considered throughout development, including dependency management, access controls, input validation, database security and review of sensitive changes.

Data protection

Protecting GovDemand data.

GovDemand may process:

  • Supplier company information
  • Supplier capability profiles
  • Government registration information
  • Procurement opportunities
  • Public government contracting data
  • Opportunity matching information
  • User account information
  • Platform activity

We apply safeguards appropriate to the type and sensitivity of the information being processed.

GovDemand's initial procurement intelligence is primarily built from public government contracting information and supplier-provided business information.

Government data

Government procurement data.

GovDemand aggregates, organizes and analyzes procurement information from government and other authorized data sources.

Where practical, GovDemand maintains source attribution so users can verify information against the original government source — each federal opportunity links back to its SAM.gov notice.

GovDemand does not alter the official government record and is not an official government system.

Account security

Account & access controls.

Controls currently operating on the platform:

  • Authenticated user accounts with verified email sign-up
  • Role-based permissions (supplier and administrator roles)
  • Protected administrative functions, checked on the server
  • Server-side API integrations — government data keys never reach the browser
  • Row Level Security on every table holding user data
  • Managed, expiring session tokens

Organization-level access boundaries for multi-user teams are planned as team accounts are introduced.

Infrastructure

Built on trusted infrastructure.

GovDemand runs on established cloud, database and edge-hosting providers. GovDemand uses infrastructure providers that maintain their own security and compliance programs.

Those programs belong to our providers; they are not GovDemand certifications.

Assurance roadmap

Building toward formal assurance.

As GovDemand grows, we intend to mature our security, risk management and control environment to support independent security and compliance assessments appropriate to our customers and market.

We are designing our operational practices with future independent assurance in mind.

Responsible disclosure

Report a security concern.

If you believe you have identified a security vulnerability or security issue involving GovDemand, please contact us promptly.

security@govdemand.com