Swiss public tenders, filtered weekly. Start free
NewsletterRadar

Security & data

Where your data lives, and what we do with it

Public-sector buyers ask these questions on the first call. Here are the answers, so you do not have to.

The source data is already public

Every award we process comes from the SIMAP API at www.simap.ch/api, which requires no authentication. Swiss public procurement awards are published by law. We do not scrape anything behind a login, we hold no confidential tender documents, and we could not leak a contract award that the Confederation has already published.

What is genuinely yours is small: your account email, the matching profile you configure, and which leads you acted on.

Hosting

The application database runs on Convex in eu-west-1, inside the EU. Fonts are self-hosted, so loading a page sends no request to Google or any other CDN.

Sub-processors

ServicePurposeRegionData
ConvexDatabase and scheduled jobseu-west-1 (Ireland)Award records, your matching profile, your lead interactions
ClerkAuthenticationSee Clerk’s own data-residency termsYour email address and session records. We never see your password
OpenRouterClassifying awards into sub-nichesRouted to the model providerPublic award text only — never your account or usage data

What the language model sees

Awards are classified into sub-niches by a language model via OpenRouter. It receives only the published award text — title, description, CPV code, procuring office, value and canton. It never receives your account data, your profile, or anything about which leads you opened. The model classifies against a fixed list; it is not asked to write anything a customer reads as fact.

Retention and deletion

Award records are kept indefinitely — they are public record and the historical archive is part of what you pay for. Your account data is deleted on request. Ask and we will confirm in writing when it is done.

A data processing agreement (DPA) is available on request before you sign.

Reporting a security problem

Email security@[PLACEHOLDER-DOMAIN]. We will acknowledge within two working days. Please do not open a public issue for anything exploitable.