Security
Your price book is your margin structure, and your bids are your pipeline. This page says how that material is protected, what is actually in place today, and where we draw the line on claims. We would rather publish a short honest page than a long impressive one.
What we will say plainly
We have not completed a formal security certification such as SOC 2. We would rather tell you that than imply one. If your procurement process requires a security review, we handle your questionnaire directly under an Enterprise agreement, with the people who built the system answering, not a portal.
How your data is handled
Your account's data, your price book, plan sets, estimates, and corrections, is scoped to your account. It is not visible to other customers, not pooled into cross-customer datasets, and not used to train anything shared across customers. CONFIRM: tenant isolation adversarial tests are gate 3 in Craig's sequence; this paragraph must not ship until he confirms the current wording matches what the tests prove
Data moves over TLS in transit and is encrypted at rest by our hosting provider. CONFIRM: Craig to verify both halves against the actual product infrastructure and name the provider on the subprocessors page
The ServiceTitan integration is read-in only. BidLine reads your price book from ServiceTitan and writes nothing back to it, or to any other system you run. Output leaves BidLine one way: an XLSX export your estimator triggers.
Who can touch it
BidLine is run by a small named team, and access to production systems is limited to the people who need it to operate the service. Our automation and research bots hold no production credentials and cannot reach customer data; that separation is an architectural rule on our side, not a policy memo.
Customer plan sets and price books are processed only inside the product. They are never moved onto the machines our marketing or research tooling runs on.
Reporting a vulnerability
If you find a security problem, write to josh@bidline.ai with enough detail to reproduce it. A founder reads that inbox, you will get a human reply, and we will tell you what we did about it. We ask that you give us a reasonable window to fix the issue before publishing anything.
What belongs in your agreement
Breach notification terms, audit support, and any control your security team needs in writing live in the data processing addendum, summarized at bidline.ai/dpa, and in your Enterprise agreement. If a claim is not on this page and not in those documents, we have not made it.