Private by default
Solicitations, company evidence, drafts, pricing, signatures, and submitted packages are designed for private organization-scoped storage.
Pre-release control overview
ContractPulsar is being built for sensitive pursuit work. Evidence, tenant access, AI activity, approvals, and final artifacts need controls that can be tested—not just reassuring language.
Security principles
The security model follows the data from official source through final receipt. These principles are implementation requirements; production claims will be narrowed to controls that have passed verification.
Solicitations, company evidence, drafts, pricing, signatures, and submitted packages are designed for private organization-scoped storage.
Organization membership—not editable profile metadata—is designed to determine workspace access at both application and database layers.
Official source records and finalized revisions are preserved. Updates create new revisions instead of rewriting prior evidence.
Privileged database credentials and model keys stay behind server boundaries and are never intended for the browser bundle.
Remote links, uploads, archives, redirects, extracted text, and model instructions are all treated as untrusted input.
Messages, meetings, signatures, price approval, and submission require explicit user authorization before an external action.
Data lifecycle
Register the source and content identity before analysis begins.
Use bounded jobs, validated extraction evidence, and least-privilege service access.
Expose citations, warnings, assumptions, and approval state to authorized users.
Apply documented retention, legal, audit, and deletion rules to each data class.
AI and external providers
AI requests are designed to run server-side with the minimum pursuit context needed for the task. Model output remains advisory until its schema, citations, deterministic checks, and required review have passed.
ContractPulsar is in pre-release development. This page does not claim SOC 2, FedRAMP, CMMC, ISO 27001, or any other third-party certification. Formal assurance statements will be published only after the relevant scope and evidence are independently verified.
Please avoid including credentials, regulated data, or complete proposal files in the first message.