Last updated 17 August 2026
Security at BOQView
BOQView is designed for commercially sensitive tender documents and evidence-backed human decisions.
Account protection
Pilot access is invitation-only. BOQView uses password authentication, six-digit email verification and recovery codes, and authenticator-app TOTP for sensitive roles and actions. Sessions can be revoked and globally signed out.
Organisation isolation
Project records and source files are separated by organisation. Database row-level security, private storage policies and server-side authority checks are tested to prevent cross-tenant access. Sensitive actions require a recently verified multi-factor session.
Document and model safety
Original files are kept in private storage and accessed through short-lived signed URLs. Deterministic parsing runs before model processing. OpenAI requests use storage-disabled mode, embedded document instructions are treated as untrusted content and model outputs cannot become confirmed evidence without validation and a human gate.
Evidence integrity
Raw evidence is immutable, interpretations are versioned and material figures retain source anchors. Totals and visualisations are calculated in code from confirmed project state. BOQView does not let a model invent or silently alter commercial numbers.
Infrastructure and monitoring
The application runs on Vercel with Supabase database and private storage. Transport uses HTTPS, security headers restrict browser capabilities and operational events use identifiers rather than tender content. Readiness, workflow failure and model spend are monitored during the controlled pilot.
Responsible reporting
Report a suspected vulnerability or data exposure to alex@deepprofessional.com. Include the affected URL, the observed behaviour and a safe way to reproduce it. Do not access data beyond what is necessary to demonstrate the issue.
Questions can be sent to alex@deepprofessional.com. Return to BOQView.