Security

Your data, handled like it matters.

TRINTA reads what your company sells and watches the public tender market on your behalf. That trust is the product, so security is not a feature we bolt on. Here is exactly how your data is protected.

01

Encryption and transport

All traffic is served over HTTPS with TLS, and the domain is on the HSTS preload list, so browsers refuse any insecure connection to trinta.ai.

Data is encrypted in transit end to end, and at rest by our hosting and database providers.

02

Hosting and data residency

TRINTA runs on European infrastructure: application compute and the Postgres database are both hosted in London, United Kingdom (Vercel and Neon, on AWS eu-west-2). Your data does not leave Europe in normal operation.

The UK is covered by the European Commission's adequacy decision, so GDPR-grade protections apply end to end. We are built GDPR-first; the Privacy Policy has the full detail on what we collect and why.

03

Your workspace is private

Every client runs in a private, branded workspace. Your keyword profile, your scored tenders, your pipeline and your notes are visible only to your team.

Access is owner-scoped and checked on every request: one client can never read another client's data, even by guessing a URL.

We never sell, rent or share your company profile or your tender pipeline. Public tender notices are public by nature; everything we learn about your business stays yours.

04

Access and authentication

Sessions use signed, HttpOnly, Secure, SameSite cookies. Login is rate-limited per account and per IP, with bot protection, to stop brute-force and credential spraying.

Administrative and internal endpoints are gated behind separate keys and fail closed if a key is missing.

05

Application hardening

A strict Content Security Policy (no unsafe-eval), X-Frame-Options DENY and frame-ancestors none (no clickjacking), nosniff, a locked-down Permissions-Policy and a strict Referrer-Policy ship on every response.

Any URL you submit (for example in the instant match) is fetched through an SSRF guard that blocks private, loopback and cloud-metadata addresses and caps the response size.

All inbound API payloads are schema-validated, size-capped and rate-limited.

06

Sub-processors

Hosting and database: Vercel and Neon (London, UK). AI processing: Anthropic and OpenAI, used to read a website and score tenders, never to train shared models on your data. Transactional email: Resend.

Product analytics run in aggregate only. The full, current list lives in the Privacy Policy.

07

For your legal and procurement team

A data processing agreement (DPA) is available for every engagement, and we complete security questionnaires as part of any evaluation. Email security@trinta.ai and we respond within one business day.

Contracts are annual, invoiced with bank transfer and purchase order support. No card details ever touch our systems.

08

Responsible disclosure

Found something? Email security@trinta.ai and we will respond quickly. We do not pursue good-faith researchers who report privately and give us time to fix.

Questions from your security or procurement team before an engagement are welcome. Reach us at security@trinta.ai. See also our Privacy Policy and Terms.