SECURITY

SECURITY

Updated at October 5th, 2026

Solicit Defence holds information Canadian defence suppliers treat as sensitive: who you are, what you build, the clearances you hold and the contracts you pursue. This page sets out how that information is protected, in transit and at rest, and who can reach it.

Encryption at rest

Everything we store for you is encrypted at rest with 256-bit AES (AES-256). That covers your account, your company profile, the tenders you track, your saved searches and every record our service keeps.

  • Files: award notices you attach to your contract history are stored with AES-256 in Galois/Counter Mode (AES-256-GCM), in a private storage bucket that is never public.
  • Records: account and profile records are held in databases encrypted with AES-256 under keys managed by Amazon Web Services.
  • Sign-in: passwords are never stored or sent in readable form; sign-in uses a challenge-response protocol, so your password does not leave your browser.
  • Logs: service logs are encrypted at rest and kept only as long as needed to run and secure the service.

Encryption in transit

Every connection to Solicit Defence is encrypted. Unencrypted HTTP is never accepted, and browsers are told to always use HTTPS for our domain (HTTP Strict Transport Security).

  • Preferred: TLS 1.3, with 256-bit AES-GCM (AES-256-GCM) offered on every connection. Current browsers connect over TLS 1.3 and choose among the strong ciphers it allows.
  • Floor: TLS 1.2. Nothing older than TLS 1.2 is accepted anywhere.
  • Files: uploading or downloading an attached document is accepted over TLS 1.3 only.

Accounts and sign-in

  • Two-step sign-in: an account with a password signs in with it and a code from an authenticator app. Text-message codes are not used.
  • Google and LinkedIn: you can instead sign in with your Google or LinkedIn account. Then your password stays with them and never reaches us, and their own sign-in protects your account, including its two-step verification if you have turned it on. We receive only your name and a verified e-mail address. If you already have an account with the same e-mail, you land in that account.
  • Verified e-mail: an account is usable only once its e-mail address has been confirmed.
  • Pilot access: during the pilot, an account reaches the product only once our team has granted access.
  • Sessions: sign-in sessions expire on their own, and signing out removes your cached profile and data from the browser.

Who can reach your data

  • Your company: your profile, tracked tenders, saved searches and attached documents are reachable only with your own sign-in. Your identity is taken from your verified sign-in, never from anything a page sends, so no request can name another company's records.
  • Our services: each part of the service runs with the narrowest permissions it needs. The service that shows you tenders can read your profile to score them, and cannot change it.
  • Our team: access to the pilot list is managed through one administrative account that requires two-step sign-in. Every change it makes is recorded permanently and reported to the whole team.
  • AI: tenders are summarised by an AI model from the public tender documents only. Your company profile is never sent to it.

Where your data is kept

Your account and all customer data are stored in Canada, in Amazon Web Services' Canada (Central) region. The website itself is delivered from a global network and stores no customer data.

Your browser

To open quickly, the product keeps a copy of your company profile in your browser's storage on your own device. It is tied to your account, never shown to anyone else who signs in on that browser, and removed when you sign out. On a shared computer, always sign out when you finish.

Reporting a concern

If you believe you have found a security issue, or you have a question about how your data is protected, contact us at info@solicitdefence.ca. We read every report and will tell you what we found.