Skip to content
iprocure

Security

Confidentiality your auditors will test.

In sourcing, the audit is who saw what, and when. iProcure is built so that the answer is always on the record, and so that the record cannot be edited after the fact.

Confidentiality

Built in, not bolted on

Need-to-know records

Restricted records are hidden even from admins. Emergency access always leaves a reason on the record that the owner can see.

Supplier-blind by construction

Suppliers never learn who else was invited. It is enforced by the product, not a checkbox someone can forget.

Sealed bids

Prices stay locked until the technical track is signed off. Supplier names can be hidden from evaluators too.

Every view logged

Watermarked downloads, expiring share links and a record of who opened what. Even an admin cannot edit or delete an audit entry.

Platform

Where it runs, who gets in

Your data, your region

Choose India, the EU, the USA or South Korea. Single-tenant and on-premises deployments are available for regulated buyers.

Identity

Single sign-on with Microsoft Entra ID, Okta and Google, with automatic user provisioning. Change someone’s access and it applies straight away.

Attachment safety

Supplier uploads are checked before they reach your team, so evaluators open files with confidence.

AI data controls

AI never awards, signs or sends anything externally without a human. Coming next: you decide which AI is used and what data it may see, including keeping prices and personal data out.

Your organisation, kept apart

Every organisation’s data, settings, roles and audit trail are kept separate from every other’s.

Accessibility

Built to WCAG 2.1 AA and the European Accessibility Act, so everyone on your team and every supplier can use it.

Certifications, stated honestly

SOC 2 Type II and ISO 27001 are build targets, and the controls above are designed to those standards. We do not hold either certificate yet and will not claim one before an auditor does. If your procurement policy requires a certificate on day one, tell us and we will share the audit timeline.

FAQ

Security questions

Can iProcure run on-premises?

Yes. Regulated buyers can run iProcure single-tenant in their chosen region or on their own infrastructure. It is the same product with the same modules, local rules and confidentiality controls, so nothing is lost by keeping your data in your own hands. We cover the options for your policy on a call.

Who can see a supplier's bid?

Only the evaluators assigned to it, and only when the event allows. Prices stay sealed until the technical evaluation is signed off, and supplier names can be hidden from evaluators too. Every time someone opens a bid, it is logged, so you can always show who saw what, and when.

What happens to data sent to AI models?

AI in iProcure suggests; a human decides. It never awards, signs or sends anything on its own, and every suggestion cites its source. Controls over which AI is used and what data it may see, including keeping prices and personal data out, are coming next. We walk through them in the demo.

Is iProcure SOC 2 or ISO 27001 certified?

Not yet. Both are targets and the controls are built to those standards, but we will only claim a certificate once an auditor has issued it. Ask us for the current audit timeline.

Next step

See it live in 10 minutes.

Pick your region and the two modules that hurt most. We run your own category through the RFx spine on sample data. No access, no commitment, no build decision required.

  • Supplier-blind RFx
  • Independent evaluation
  • Approvals from email
  • Global & modular

Design partner's seat

Pre-launch and honest about it: you get the mechanism now. Design partners get a free 60 to 90 day pilot, a preferential launch price, roadmap input and a direct line to the founders.

Call +91 70990 38346WhatsApp us