Do not upload CUI, classified information, export-controlled technical data, or sensitive customer data in this MVP. BidShield AI does not certify CMMC compliance.

Security posture

Built with explicit MVP boundaries

BidShield AI is defense-adjacent software, so the public website, app, and exports keep operational limits visible. The current product is for public-only solicitation readiness workflows, not controlled-data handling.

View app settings

Important MVP limitation

Do not upload CUI, classified information, export-controlled technical data, or sensitive customer data. BidShield AI does not certify CMMC compliance.

No-CUI MVP boundary

The MVP policy prohibits CUI, classified information, export-controlled technical data, and sensitive customer data. The analyzer requires explicit public-only acknowledgment, but production DLP, malware scanning, retention, and access controls are still required.

Authenticated workspace data

Customer workspace flows use Supabase authentication and organization-scoped database records. Tenant tables are designed around row-level security policies and are checked through launch smoke tests before controlled pilots.

Tenant isolation controls

Tenant-scoped tables include organization_id, server-side organization checks, and Supabase RLS policies for member/admin access.

Audit trail roadmap

The schema includes audit_logs for uploads, analyses, exports, evidence changes, profile changes, and billing events. Expanded route-level audit writes remain a launch-hardening item.

Before production

The trust checklist is part of the product

These controls and remaining review gates are intentionally visible because trust is part of the buyer experience in this category.

Public-only intake and no-CUI operating policy

Supabase RLS policies applied and smoke-tested for tenant tables before pilot expansion

Security review and threat model before controlled-data expansion

LLM provider retention and no-training review

Legal/compliance review for customer-facing claims

Verified official CMMC/FAR/NIST mappings before certification-adjacent use