Your pipeline is yours alone
TenderMetro combines openly published tender data with your private capture work. The public data is fully sourced and verifiable; your pipeline, saved searches, notes and contact groups are isolated to your account by design.
215
Named public sources
284,565
Tenders from public records
230
Countries covered
None
Private data shared
Security
How the platform is protected
Security controls are enforced in the database itself, not just in the interface, so a bug in one screen cannot expose another account's data.
Row-level access control
Every private table — pipeline, notes, saved searches, alerts, contact groups, API keys, webhooks — is restricted per account at the database layer. Requests are authorised as your user, not as an administrator.
Encryption in transit and at rest
All traffic is served over HTTPS with modern TLS. Databases, backups and file storage are encrypted at rest by the managed infrastructure we run on.
Hashed API credentials
API keys are shown once and stored only as a hash with a short prefix for identification. Webhook payloads are signed with HMAC-SHA256 so you can verify every delivery.
Least-privilege contact data
Buyer contact details published on tender notices are served through capped, audited lookups rather than open table access, which prevents bulk copying of personal data.
Isolated AI processing
AI briefs and the analyst chat send only the tender context needed to answer, and outputs are stored against your account. Your data is not used to train third-party models.
Monitored collection pipeline
Collection jobs run on fixed schedules with failure counters, automatic pausing and a public status page so data problems are visible rather than silent.
Provenance
Every record traces back to its publisher
TenderMetro does not invent numbers. Each tender, award, buyer and supplier record carries its source, its source identifier and a link back to the original notice.
- Only openly published procurement information is collected — official portals, national registers, development banks and UN agencies
- Source, reference and original URL stored on every record so any figure can be checked at the publisher
- Award history kept from 2020 onward for consistent trend analysis
- Completeness scoring per source, with weak records rejected instead of silently imported
- Full source register and refresh intervals published on the coverage page
- Estimated fields — expiry projections, forecasts, fit scores — are labelled as projections wherever they appear
292,827
Records with provenance
0
Sources refreshed 24 h
16,212
Documents linked
24,030
Buyer profiles
Privacy
What we hold, and what we never do
We keep the minimum needed to run your account and your pipeline.
What we store
- Your account details: name, email, company, country, role
- Your work: pipeline pursuits, notes, saved searches, alerts, contact groups, exports
- Operational logs: sign-ins, API requests, email delivery events, collection runs
What we never do
- Sell or rent your personal data or your pipeline to anyone
- Show your pursuits, notes or saved searches to other customers
- Use your private capture data to train third-party AI models
- Email addresses that have bounced or unsubscribed — suppression is enforced before every send
Questions
Common trust questions
Where is my data hosted?
On managed cloud infrastructure with encrypted storage and automated backups. Application requests are served from an edge network, and database access is restricted to the application layer.
Can other customers see my pipeline?
No. Pipeline pursuits, notes, saved searches, alerts and contact groups are scoped to your account in the database, so another signed-in customer cannot read them even through the API.
Is the tender data legal to use?
Yes — TenderMetro collects only information that buyers publish openly for suppliers to act on, and every record links back to the publisher's own notice.
How do you handle personal data on tender notices?
Contracting-officer names, roles and published contact details are shown to signed-in users through capped lookups for legitimate bidding contact. Bulk table access is not available, and we remove details on request.
How do I delete my account and data?
Ask us from your account or by contacting support and we will delete your account, pipeline and personal data. Aggregate public procurement records remain, as they are not yours or ours.
How do I report a security issue?
Contact us through the sales and support form with the details. We investigate reported vulnerabilities promptly and will confirm receipt.
Verify before you rely on it
Check live platform status and the full register of sources behind every figure in TenderMetro.