Trust & Security
Procurement evidence is your most sensitive data. We treat it that way.
We don't lead with our techstack. We lead with what we commit to — and how we enforce it.
Six commitments to your security team
Every one of these is enforced in production today, not on a roadmap.
Your evidence, your control.
Every document you upload is encrypted at rest, scoped to your tenant, and never used to train any model. Delete a tenant and the evidence, chunks, embeddings, and scores are purged within 30 days.
- AES-256 at rest in Supabase Storage + Postgres
- Zero-data-retention contracts with Anthropic + Cohere
- Hard deletion guarantee within 30 days of tenant removal
Audit-ready by default.
Every write — score, comment, evidence upload, role change — is logged with actor, timestamp, before/after payload. Exportable as CSV. Your auditors don't need to re-run the analysis.
- Append-only audit_log table; admin-only export
- Per-tenant visibility — no cross-tenant audit data
- All AI scores carry model, version, prompt template version, and cost
Data resident where you operate.
Primary region is me-central-1 (UAE). EU option (eu-central-1, Frankfurt) available on the Continuous tier for European subsidiaries. No cross-region replication of evidence.
- Default: me-central-1 (Dubai)
- Optional: eu-central-1 for EU clients — chosen at workspace creation
- Region is enforced at the Supabase project level, not just config
Access you control.
OAuth via Google + Microsoft out of the box. Three-role RBAC (Owner, Contributor, Viewer) with tenant-scoped invitations. Revoke any user, any time, with effect under 60 seconds.
- Google + Microsoft OAuth; SAML on Continuous + White-Label
- Tenant-scoped invitations with signed JWTs and 72-hour expiry
- Revocation flushes session within one minute via JWT TTL
AI without the privacy trade-off.
Every model call goes through CollectiveSpend's own API key under zero-data-retention contracts. Your evidence never sits in a model training corpus. Per-tenant cost cap prevents runaway bills.
- ZDR with Anthropic + Cohere — model providers can't see across tenants either
- Per-tenant monthly cost cap with kill switch
- Every LLM call is logged with model, tokens, cost — admin-visible
Strict tenant isolation.
Row-level security on every tenant-scoped table — enforced at the Postgres layer, not just the app. Even a compromised application key cannot read across tenant boundaries.
- Postgres RLS on every tenant-scoped table from migration #1
- JWT-injected tenant_id claim drives all policy decisions
- RAG retrieval filtered by tenant_id at SQL level, not just code
Compliance roadmap
What's live, what's in progress, what's planned. We won't claim a standard we haven't actually achieved.
- Live
GCC data residency
me-central-1 (UAE) primary. Available to every tenant on every paid tier today.
- Live
Data Processing Agreement (GDPR + UAE PDPL)
Standard DPA available on request. Covers GDPR Article 28 + UAE PDPL Article 21 obligations.
- In progress
ISO 27001:2022
Our own certification cycle is in progress. Pre-audit security questionnaire available now on request.
- Planned
SOC 2 Type II
Planned. We'll publish the auditor and scope before the audit window opens.
- Planned
SAML SSO + SCIM provisioning
On the roadmap for the Continuous + White-Label tiers. Google + Microsoft OAuth live today.
Sub-processors
Third parties that process your data on our behalf. Every entry has a public DPA — click the name to verify.
| Vendor | Purpose | Region |
|---|---|---|
| Supabase | Postgres database, authentication, file storage | me-central-1 |
| Vercel | Application hosting + edge compute | dxb1 / fra1 |
| Anthropic | LLM API for scoring, verification, and content generation | us-east |
| Cohere | Multilingual embeddings (EN + AR) for retrieval | eu |
| Resend | Transactional email (invitations, reports, notifications) | ap-northeast-1 |
| Inngest | Durable background workflows (bulk scoring, recommendations) | us |
| Upstash | Rate limiting + ephemeral cache | eu |
| Sentry | Error tracking + performance monitoring | eu |
| PostHog | Product analytics (anonymous usage telemetry) | eu |
Incident response
Severity-1 incidents (data exposure, prolonged outage) trigger notification to all affected tenants within 24 hours via the primary contact on file. Full post-mortem published within 7 days.
Security contact
Responsible disclosure, security questionnaires, DPA requests — one inbox, monitored daily by the CTO.
security@collectivespend.comDocuments on request
We don't post these publicly because we want a real conversation with your security team — fastest way is to email us: