Security, Data Handling & Compliance
What you may upload, how your data is protected, and our NIST SP 800-171 aligned compliance roadmap.
Version 2026-07-07 · What you may upload, how your data is protected, and our NIST SP 800-171 aligned compliance roadmap.
1. Scope of service — what you may upload
Octobid is designed for publicly posted solicitations and your company's own business information (capability statements, past-performance summaries, draft proposals). Octobid is NOT an authorized environment for Controlled Unclassified Information (CUI) as defined by 32 CFR Part 2002, nor for classified material of any kind.
Do not upload documents marked CUI, ITAR/EAR-controlled technical data, or other export-controlled material. Solicitation packages that agencies publish for open competition are public information and are appropriate to upload.
2. Current security controls
Encryption in transit and at rest: all traffic is TLS-terminated at the edge; stored documents live in private object storage; off-site disaster-recovery snapshots are encrypted with AES-256 before leaving the primary host.
Tenant isolation: every workspace's documents, proposals, and company facts are scoped to its own tenant at the database and object-storage layer.
Hardened runtime: application containers run read-only with dropped Linux capabilities and no privilege escalation; SSH access is key-only; brute-force protection and least-privilege service accounts are enforced.
Backups and recovery drills: daily database backups, an encrypted remote mirror on independent infrastructure, and a weekly automated restore drill that verifies backups actually restore.
Email authentication: SPF, DKIM, and DMARC (p=quarantine) protect our domain against spoofing.
AI data handling: your documents are used to generate your drafts. We do not train models on your content, and we never share proposal content across tenants.
3. Compliance roadmap
NIST SP 800-171 self-assessment (in progress): we maintain a System Security Plan (SSP) and a Plan of Action & Milestones (POA&M) mapped to the 110 controls of NIST SP 800-171, reviewed quarterly.
SOC 2 (planned): a SOC 2 Type I examination is on our roadmap, followed by Type II. Timing will be published on this page when the engagement is scheduled.
We publish this page so procurement and security teams can evaluate us honestly: what we do today, what we are building next, and what the platform is — and is not — intended for.
4. Reporting a security concern
Email [email protected] with the subject "SECURITY". We acknowledge reports within two business days.