Skip to content
AwardBeam

Security

Security you can check before you sign.

Every control on this page is enforced by the product today, and every status is dated. Where AwardBeam does not hold a certification yet, the table says so in plain words.

  1. A staff console for the City of Westbridge, signed in as Sarah Chen, lists the actions that also require an authenticator code: recording a bid opening, downloading a bid file, publishing an award including the intent to award, and opening or exporting the audit log.
  2. For each one, a card titled Confirm it is you asks for the 6-digit code from an authenticator app. AwardBeam cannot open protected staff actions until the code is accepted.
  3. Each of the four actions is confirmed in turn.
  4. Staff idle limit: 30 minutes by default, configurable from 5 to 120 minutes.

Demonstration data. The City of Westbridge is a fictional municipality.

Controls

Controls the product enforces today.

Each statement describes the current release and is backed by the product itself. Where a control has a limit, the limit is written next to it.

Enforced in the database

Sealed until the opening is recorded

Before the opening, bid contents are unreadable to every staff account, administrators included. Administrators see a count and the time each bid arrived. The opening can be recorded only after the deadline, only once, and only through the product.

Enforced in the database

Row-level security on every table

Access rules live in the database itself. Whether a request comes from a screen or goes straight to the database, the database decides what that account may read, so a direct request gets nothing a screen would refuse.

Staff accounts

An authenticator code for sensitive actions

Recording a bid opening, downloading a bid file, publishing an award and opening the audit log each require a code from the staff member's authenticator app. So do changes to approval rules, staff roles and the idle limit.

Enforced in the database

An audit trail that refuses edits

Every recorded action is appended with who did it and when, and keeps the values before and after. The database refuses to change or delete an entry for every application account, including administrators and the service key.

Product setting

Idle sign-out for staff

Staff sessions sign out after 30 minutes without activity by default. An administrator can set the limit anywhere from 5 to 120 minutes. It is a product setting.

Enforced in the database

Bid versions with a content hash

Each submission is saved as a version with a confirmation number, a server timestamp and a SHA-256 content hash. A recorded version cannot be edited, and confirmation numbers are never reused.

Enforced in the product

Every file download is logged

Downloads of bid files, solicitation documents, addenda, contracts, vendor compliance files and protest documents record who downloaded which file, and when.

Enforced by the sign-in form

Lockout after failed sign-ins

Five failed sign-ins for one address inside fifteen minutes lock it for fifteen minutes, for staff and contractor accounts alike. The answer is the same whether or not an account exists, and a staff lock is written to the audit trail.

Enforced in the product

Uploads are inspected, not just named

Every upload is opened and checked. Programs and scripts are refused whatever their name, and so are web pages, macro-enabled Office files, archives that hold a blocked file, and files whose contents do not match their extension.

Demonstration data. The City of Westbridge is a fictional municipality.

Sealed bids

Who can read a bid, and when.

Before the deadline, an administrator sees a count and the time each bid arrived, and nothing else. The deadline passing opens nothing. Contents unlock only when an authorized officer records the opening, which takes an authenticator code and can happen once.

See the bid opening on the product page
  1. While bidding is open, September 22 to 24. What each can read: Sarah Chen (administrator): count and receipt times; Marcus Webb (evaluator): nothing; Clearwater Pump & Well (bidder): its own bid; Other bidders (vendors): nothing from other bids; Residents (no account): the solicitation.
  2. When the deadline passes at 2:00 PM ET. What each can read: Sarah Chen (administrator): count and receipt times; Marcus Webb (evaluator): nothing; Clearwater Pump & Well (bidder): its own bid; Other bidders (vendors): nothing from other bids; Residents (no account): the solicitation.
  3. When the opening is recorded at 2:01 PM ET. Sarah Chen records the opening with an authenticator code. Five bids were present. What each can read: Sarah Chen (administrator): all bid contents; Marcus Webb (evaluator): assigned bids, after a cleared conflict declaration; Clearwater Pump & Well (bidder): its own bid; Other bidders (vendors): nothing from other bids; Residents (no account): the solicitation.
  4. After the award is published. What each can read: Sarah Chen (administrator): all bid contents; Marcus Webb (evaluator): assigned bids, after a cleared conflict declaration; Clearwater Pump & Well (bidder): its own bid, the award and the tabulation; Other bidders (vendors): award and tabulation; Residents (no account): award and tabulation.

Demonstration data. The City of Westbridge is a fictional municipality.

Audit trail

An audit trail that refuses edits.

Every recorded action is appended with who did it, when, and the values before and after. The database refuses to change or delete an entry for every application account, administrators and the service key included.

Before and after values
Each entry keeps the old value and the new one, so a reviewer sees exactly what moved.
Refused by the database
The refusal comes from the database itself, so it holds for a request that never touches a screen.
Read with an authenticator code
Administrators in your agency open the log, and export it, after confirming a code.
  1. The Audit log of the City of Westbridge, newest first: Change Order #2 recorded on C-26-0041 ($42,500) (Diane Foster, Sep 24, 4:05 PM); Award published: FAC-26-104 to Horizon Mechanical (Sarah Chen, Sep 24, 3:12 PM); Sealed bids opened for UTIL-26-086: 5 received (Sarah Chen, Sep 24, 2:01 PM); Addendum #1 issued for PW-26-118 (Diane Foster, Sep 23, 4:40 PM); Bid WB-PW-26-118-BID-0001 received for PW-26-118 (System, Sep 23, 4:18 PM).
  2. A notice above the table reads: These records cannot be edited or deleted.
  3. The change order entry shows its before and after values: state Awaiting approval to Executed, contract value $3,905,000 to $3,947,500.
  4. Sarah Chen, an administrator, tries to change the amount on that entry. The database answers: audit events cannot be modified or deleted.
  5. A caller holding the service key tries to delete the entry. The database answers: audit events cannot be modified or deleted.
  6. The entry stays exactly as it was recorded.

Demonstration data. The City of Westbridge is a fictional municipality.

Status

Dated status, gaps included.

Every row carries the same date. Where AwardBeam has no certification or has not completed a review, the row says so in the same words a security questionnaire uses.

Available today
6
Not in place yet
6

Status as of September 2026

Access control enforced by row-level security in the database
Available

On every table, so a direct request to the database gets no more than a screen would show.

Authenticator code for bid openings, bid downloads, award publishing and the audit log
Available

Also required to change approval rules, staff roles or the idle limit. Contractor accounts are not asked to enroll.

Append-only audit trail with before and after values
Available

The database refuses edits and deletes, including from administrators and the service key.

Staff sessions sign out after idle time (30 minutes by default)
Available

An administrator can set 5 to 120 minutes. It is a product setting.

Five failed sign-ins lock the address for 15 minutes
Available

Applies to staff and contractor accounts in the sign-in form. The same answer is given whether or not an account exists.

Uploads inspected: programs, scripts and macro files are refused
Available

Content inspection, not antivirus scanning: it stops the file types used to deliver malware.

Single sign-on
Not available

Staff sign in with an email address and password.

SOC 2 Type II report
Not held
Independent penetration test
Not yet performed
Accessibility conformance report (VPAT 2.5)
Not yet published

See the accessibility statement.

GovRAMP authorization
Not held
TX-RAMP certification
Not held
CJIS
Not applicable

AwardBeam holds procurement records, not criminal justice information.

Data classification

Sensitive records: who can read them, and when.

Most procurement records become public once an award is published. These are the exceptions, and the database enforces each rule.

Unopened bids

Who can read it
Administrators see a count and the time each bid arrived. Evaluators see nothing. Each bidder sees only its own bid.
When that changes
After the deadline passes and an authorized officer records the opening with an authenticator code, once. Then administrators read all bids, and assigned evaluators read them after a cleared conflict declaration.
What the public sees
After award

Bid amounts on the award page. Sealed bids are left out of records packets and exports.

Price envelopes

Two-envelope solicitations

Who can read it
Nobody, after the technical opening. Technical answers and files are readable. Amounts are not shown, and bids are not ranked by price.
When that changes
A separate price opening, recorded after the technical opening. An award cannot be made while prices are sealed.
What the public sees
After award

Prices on the award page.

Evaluator scores and notes

Who can read it
Each evaluator reads their own. Administrators read the whole panel's.
When that changes
Individual scores and notes stay internal after the award.
What the public sees
Averages after award

Committee averages by criterion, from submitted scorecards. Individual notes are never public.

Taxpayer IDs

Who can read it
The vendor profile stores only the last four digits of an EIN or TIN. The vendor reads its own. Staff read it for vendors their agency has a bid, invitation or contract with, or that are new to the platform.
When that changes
Does not change.
What the public sees
Never public

Left out of public pages, records packets and exports.

Government estimates

Who can read it
Any staff account in your agency.
When that changes
When the award is published, the estimate is copied to the public award page.
What the public sees
After award

The estimate on the award page. An estimated range appears on the opportunity page only if your agency publishes one.

Audit log

Who can read it
Administrators in your agency, after confirming an authenticator code.
When that changes
Does not change.
What the public sees
Never public

Gaps

What is not available yet.

IT reviewers ask about these first, so each one is listed here with what happens today. The security packet lists every known limitation and its planned fix, including ones that are not published on this page.

Not available

Single sign-on

Today: Staff sign in with an email address and password. There is no connection to your agency's identity provider yet.

Not available

Authenticator codes for contractors

Today: Contractor accounts sign in with a password only. They are not asked to enroll, including when they download their own bid files.

Reporting and review

Report a problem, or ask for the packet.

Report a vulnerability

Use the contact form. There is no public security mailbox, and the site's security.txt file points to the same form. Include what you found, the steps to reproduce it and the page involved. Please do not access or change data that is not yours.

The security.txt file lists the contact form as the contact, expires on September 24, 2027, prefers English and names this page as the policy.

For IT and legal review

Request the security packet

The packet includes the subprocessor list: the companies that host or process data for AwardBeam. There is no NDA to click through before you ask. If your agency has its own security questionnaire, send it with the request.