OctobidOCTOBIDPublic Tender Gazette

octobid.net

Trust Center

What we run, how it is monitored, and the evidence behind it — published for security reviewers and procurement teams.

⚠ Attention items open · snapshot 2026-07-19 · NIST 800-171 self-assessment 103/110 (self-assessment 2026-07)

Controls in production

  • Encryption everywhere. TLS at the edge; documents in private object storage; AES-256 encrypted off-site disaster-recovery snapshots on independent infrastructure.
  • Tenant isolation. Every workspace's data is scoped to its tenant at the database and object-key level.
  • Hardened runtime. Read-only containers, dropped Linux capabilities, no privilege escalation, key-only SSH, brute-force protection.
  • Backups that restore. Daily database backups, an encrypted remote mirror, and a weekly automated restore drill that proves recovery works.
  • Continuous monitoring. Graded alerting (major / warning / notice) on data pipelines, backups, and services; monthly container vulnerability scans.
  • Change control. Every production change passes type checking and lint gates and ships through scripted, logged deploys from version control.
  • AI data handling. Your documents generate your drafts. We never train models on customer content or share content across tenants.

Compliance posture

  • NIST SP 800-171.Documented SSP and POA&M, first scored self-assessment 103/110 (July 2026), quarterly reviews scheduled.
  • SOC 2. Audit-ready: policy set adopted, system description drafted, evidence collected automatically every month into an auditor-ready package. A Type I examination by an independent CPA firm will be engaged on customer demand; this page will host the report.
  • Scope. Octobid is not an authorized environment for CUI or export-controlled material — see the Security & Data Handling policy.

Security reviewers: request the current evidence package or ask questions at [email protected] (subject SECURITY). We answer within two business days.