Security & residency
Know exactly where your bid data lives.
EstiWright is built for contractors whose tenders can't touch a public cloud — government, defence-adjacent, and confidential commercial work. Three deployment tiers, row-level isolation enforced by the database, and every output approved by a human. Here is exactly how.
Posture at a glance
The short version
Three deployment tiers
Cloud (EU-hosted), dedicated UAE, or the on-prem edition. Your tier decides where the data physically lives.
Row-level isolation
PostgreSQL Row-Level Security, forced on every tenant table. One tenant physically cannot read another's rows.
Your keys, your infra
Provider keys live in your environment / secret store — never the application database.
Human-approved
The AI drafts; an engineer signs off. Nothing ships without a recorded, attributable approval.
Auditable
Append-only usage and event logs behind every AI call, sign-off and config change — read and add, never rewrite.
Governed spend
Transparent AI metering by department and model, with soft alerts and hard budgets you set and enforce.
01 · AI routing
You choose which models see your tender.
The AI gateway is a single, sanctioned path, and the routing mode is a per-tenant switch — no re-platforming, no code change. Routing controls which models run; your deployment tier controls where the data lives.
On-prem
Every AI call is clamped in-network — available with the on-prem edition, where the whole platform runs inside your infrastructure. Routing alone does not move a hosted tenant out of the EU.
Hybrid
Local-first, with a cloud fallback for the hardest reasoning — and you decide which tasks are ever allowed to use it. Sensitive work stays local by default.
Cloud
Managed models when isolation isn't required and speed matters most. The same guardrails — metering, budgets, audit — apply in every mode.
02 · Tenant isolation
Enforced by the database, not just the app.
Multi-tenant SaaS usually trusts application code to scope every query. EstiWright doesn't rely on that. Isolation is enforced one layer below the app — in PostgreSQL itself.
- Row-Level Security on every tenant table, with
FORCE ROW LEVEL SECURITY— the rule applies even to the table owner. - Non-privileged role — the app connects as a role that cannot bypass RLS, with the tenant pinned per transaction.
- No cross-tenant read — even a bug in application code cannot return another tenant's rows; the database refuses them.
03 · Keys & data residency
Three tiers. Know which one you're on.
Where your bid data physically sits is decided by your tier — not by a setting. We publish the ladder rather than let you assume, because a security review will find the answer anyway.
-
Cloud
EU-hosted — the standard plan
Starter, Pro and Agency run on our shared platform in Frankfurt (EU). Tenant-isolated by PostgreSQL row-level security, human-approved, and never used to train models. This tier is not in-region for the Gulf, and it does not offer zero egress.
-
Dedicated
Single-tenant in the UAE
A dedicated single-tenant deployment in AWS
me-central-1, provisioned on signed demand. Worth being precise here: Saudi law does not require in-Kingdom hosting for private commercial data — the NCA removed that control in ECC-2:2024, and both Saudi and UAE PDPL permit cross-border transfer under standard contractual clauses. Choose this tier for procurement preference, a contractual residency clause, or government and critical-infrastructure work where in-Kingdom operation still binds. Priced above Agency. -
Sovereign
On-prem, inside your network
The on-prem edition runs entirely on your own infrastructure. This is the only tier with genuine zero egress — no prompt, document or price leaves your network, because nothing of ours is running outside it.
Secrets stay out of the database
Cloud provider API keys are read from your environment or secret store and never written to the application database — a leaked backup never yields a usable key.
Deploy where you must
Run EstiWright on-prem, in your own cloud account, or your VPC. The platform doesn't require a managed multi-tenant host you don't control.
In-region on request
The standard plan is EU-hosted. For UAE/KSA residency, the dedicated tier runs single-tenant in AWS me-central-1.
04 · Access, approvals & audit
Every action has an owner and a record.
-
Identity
SSO or signed tokens
Single sign-on (Wright ID) or short-lived signed tokens — access and refresh tokens are separate and type-checked, so one can't stand in for the other.
-
Roles
Least-privilege access
Super-admin, local-admin, engineer and viewer roles, with guardrails that stop a tenant from ever locking itself out of its own administration.
-
Approvals
Human-in-the-loop
The AI drafts requirements, compliance positions and proposals; a person approves each one. Every sign-off is timestamped and attributable.
-
Audit
Append-only trail
AI calls, approvals and configuration changes are logged to an append-only record — it can be read and added to, never quietly rewritten.
-
Governance
Spend you control
Per-department and per-model metering, soft alerts, and hard budgets that refuse further spend when a ceiling is reached — fail loud, bill visibly.
-
Evidence
Defensible outputs
Because the pipeline is deterministic and every position is signed off, a proposal comes with the trail that produced it — not an unexplained AI answer.
05 · What we don't do
Just as important as what we do.
We don't train on your data
Your tenders, requirements and pricing are never used to train models.
We don't share your tenders
Bid data isn't sold, brokered, or handed to third parties. It's yours.
We don't force egress
In on-prem mode, using EstiWright never requires your data to leave your network.
Have a security questionnaire?
Send it. We'll answer against the actual architecture — not a brochure. Formal attestations are on our roadmap; today we'll walk your team through the design, the deployment model, and how it maps to your controls.