Security
How eProcurement.si protects accounts, documents and procurement records, and where the limits are.
- Encrypted connections. Every page is served over HTTPS, with strict transport security, so traffic cannot be read or altered on the way.
- A strict content policy. The site only runs its own scripts and the Firebase libraries it needs. Inline scripts, plugins and framing by other sites are blocked, which limits cross-site scripting and clickjacking.
- Sign-in by Google Firebase Authentication. We never see or store your password. Email verification is required before you can upload documents, publish notices or submit offers, which limits fake and automated accounts.
- Access rules enforced on the server. What each person may read or change is decided by database rules, not only by the screens you see. Offers are private to the buyer and the vendor. Vendors cannot see each other's bids. Drafts are private to their owner. A completed contract cannot be edited.
- Careful handling of PDF documents. Only PDF files are accepted, up to 4 MB each and 40 per account. The file signature is checked on the server. PDFs that contain scripts, embedded files or password protection are rejected. Each file is fingerprinted with SHA-256 and verified again on download, and PDFs are saved to disk, never opened inside the page.
- Documents shared only on purpose. A vendor's documents are private until the vendor attaches them to an offer. They are then shared with that buyer only. Sharing cannot be reversed, so the buyer keeps what they evaluated.
- Data kept in Europe. Account and procurement data is stored in Google Cloud Firestore in a European multi-region location.
What to know
- PDFs are not virus-scanned. Our checks reduce risk but cannot prove a file is safe. Open documents only from parties you trust, and keep your PDF viewer up to date.
- This is an early preview. We have not been through a formal security certification such as ISO 27001 or SOC 2. Do not upload highly sensitive information yet.
- No payments are processed here. The platform records payments you make elsewhere. It does not hold card or bank details.
- Protect your account. Use a long, unique password, verify your email and sign out on shared computers.
Report a vulnerability
If you find a security problem, please tell us privately through the contact form on the platform page, and give us reasonable time to fix it before you share details. Please do not access other people's data, disrupt the service or test with automated scanners at volume. Our disclosure details are in security.txt.