Its One App, LLC · its1bid.com · Updated August 2026
Sealed submissions are encrypted on arrival and are designed to be unreadable — including by us — until the solicitation's published opening time. Unsealing before the opening timestamp is refused by the system, not by policy: early attempts are denied and written to an append-only, tamper-evident audit log with the actor, timestamp and result. Every submission receives a SHA-256 integrity receipt, submission cutoffs are enforced by the server clock, and late submissions are refused automatically with no administrative override.
Traffic is encrypted in transit (TLS 1.2+) and data is encrypted at rest (AES-256). The platform runs on Google Cloud infrastructure whose data centers hold SOC 2 and ISO 27001 certifications (those certifications are Google's; our own SOC 2 Type II audit and a StateRAMP roadmap are planned ahead of state-agency deployments, and we say so plainly rather than borrowing our host's letterhead). Secrets live in Google Secret Manager; payment card data never touches our systems (Stripe, PCI-DSS Level 1).
Customer content — profiles, uploads, bids, evaluations — is never used to train AI models. Document parsing calls process your file to extract requirements and return the result; extracted content stays inside your tenant.
Data is segregated per tenant with tenant-scoped credentials and per-tenant storage namespaces. Administrative actions, credit movements, unsealing events and preference adjustments are journaled for the certified administrative record a protest will demand. For platform outages affecting a deadline, the issuing entity controls any extension and the platform logs and publishes it — see our Terms.
AI on this platform assists — it never decides. Where AI could be a substantial factor in a consequential decision (scoring proposals, flagging responsiveness), heightened-scrutiny controls apply, aligned with the NIST AI Risk Management Framework and state AI-governance law (including the Texas Responsible AI Governance Act): every AI-assisted evaluation carries a clear, plain-English disclosure; AI output is an advisory first pass that a human evaluation committee with override authority must adopt, adjust, or discard; the AI receives no protected-class information and never scores vendors on anything beyond the published rubric applied to their submission; every AI evaluation run is written to the append-only audit log; and every solicitation carries a human-reviewed statutory protest channel. AI never auto-rejects a bid and never denies anyone access to a government service.
Report suspected vulnerabilities to support@its1app.com with "SECURITY" in the subject. We acknowledge within one business day and do not pursue good-faith researchers.