Security

Business procurement data only. No patient data workflow.

The product is designed to match company capabilities with public procurement information while keeping clear boundaries around access, evidence, and sensitive data.

Evidence before assumptionsUnknown requirements stay visible.
Source-linked reportsSee the reason behind each conclusion.
Deadline-awarePreparation time is part of the match.

Product boundaries

Security starts with collecting less.

No PHI

Patient names, diagnoses, medical records, insurance identifiers, and treatment data are prohibited.

Tenant isolation

Production is designed around organization membership, row-level security, roles, and audit history.

Evidence boundaries

Procurement documents are untrusted content and cannot override system rules or access secrets.

No-PHI boundary

What belongs in the profile—and what does not

Allowed business information

  • Business name, website, and address
  • Work contact information
  • Services, products, and coverage
  • Business licenses and certifications
  • NAICS, UEI, CAGE, and SAM status
  • Public procurement information

Do not enter

  • Patient names or medical records
  • Diagnoses or test results
  • Patient insurance identifiers
  • Treatment dates or billing records
  • Anything linking a person to care
Bizmetria does not claim HIPAA, SOC 2, FedRAMP, or other certification without completed verification. Live release requires separate security, privacy, and legal review.