Trust & Security
How we handle your data
This page is maintained by Concourses to answer common security and privacy questions about the Concourses platform. It describes controls we currently operate and is not an independent certification. Security is a shared responsibility between Concourses, our infrastructure providers, and our customers.
Access & authentication
- Sign-in is handled by our authentication provider with email and password or Google sign-in.
- Application data is scoped per organization. Row-level security rules in the database restrict each request to the records the signed-in user's organization is entitled to.
- Access to RFP catalog data and stored documents requires an active subscription on the user's organization.
- Administrative actions (managing org members, billing, internal admin tools) require an admin role on the organization.
Platform & hosting
- The application runs on a managed serverless edge runtime. Data is stored in a managed Postgres database with row-level security enabled on customer-data tables.
- Traffic to the application and APIs is served over HTTPS.
- Server-side secrets are stored in the platform's secrets manager and are not exposed to browser code.
Data we collect & how it's used
- Account data: name, email, organization membership, and authentication identifiers.
- Product data: saved searches, watchlist entries, notifications, and activity needed to operate the service.
- Billing data: subscription status and a customer identifier from our payments processor. Card numbers are handled by the processor and never stored by Concourses.
- Inbound email content sent to Concourses addresses for RFP capture is stored for processing and review by Concourses operators.
Subprocessors & integrations
Concourses relies on the following categories of subprocessors to operate the service:
- Cloud hosting and managed database / storage.
- Authentication provider for sign-in.
- Payments processor for subscription billing.
- Transactional and inbound email provider.
- AI model gateway used for document and listing extraction.
- Optional customer-authorized integrations (e.g. Microsoft Graph, SharePoint) connected by an organization admin.
Contact us for the current list of named subprocessors used in your deployment.
Retention & deletion
- Account, organization, and product data is retained while the organization has an active or recently-cancelled subscription.
- Customers can request deletion of their account or organization data by contacting us at the address below.
- Backups taken by our infrastructure providers may persist for a limited period after deletion before being overwritten.
Security contact & reporting
To report a security issue, ask a privacy question, or request a copy of the current subprocessor list, contact security@concourses.app. We aim to acknowledge security reports within two business days.
This page reflects current practices and may be updated as the product evolves. It does not constitute legal advice or a contractual commitment beyond what is set out in your agreement with Concourses.