Security & residency

Know exactly where your bid data lives.

EstiWright is built for contractors whose tenders can't touch a public cloud — government, defence-adjacent, and confidential commercial work. Three deployment tiers, row-level isolation enforced by the database, and every output approved by a human. Here is exactly how.

Posture at a glance

The short version

Three deployment tiers

Cloud (EU-hosted), dedicated UAE, or the on-prem edition. Your tier decides where the data physically lives.

Row-level isolation

PostgreSQL Row-Level Security, forced on every tenant table. One tenant physically cannot read another's rows.

Your keys, your infra

Provider keys live in your environment / secret store — never the application database.

Human-approved

The AI drafts; an engineer signs off. Nothing ships without a recorded, attributable approval.

Auditable

Append-only usage and event logs behind every AI call, sign-off and config change — read and add, never rewrite.

Governed spend

Transparent AI metering by department and model, with soft alerts and hard budgets you set and enforce.

01 · AI routing

You choose which models see your tender.

The AI gateway is a single, sanctioned path, and the routing mode is a per-tenant switch — no re-platforming, no code change. Routing controls which models run; your deployment tier controls where the data lives.

On-prem

Every AI call is clamped in-network — available with the on-prem edition, where the whole platform runs inside your infrastructure. Routing alone does not move a hosted tenant out of the EU.

Hybrid

Local-first, with a cloud fallback for the hardest reasoning — and you decide which tasks are ever allowed to use it. Sensitive work stays local by default.

Cloud

Managed models when isolation isn't required and speed matters most. The same guardrails — metering, budgets, audit — apply in every mode.

02 · Tenant isolation

Enforced by the database, not just the app.

Multi-tenant SaaS usually trusts application code to scope every query. EstiWright doesn't rely on that. Isolation is enforced one layer below the app — in PostgreSQL itself.

  • Row-Level Security on every tenant table, with FORCE ROW LEVEL SECURITY — the rule applies even to the table owner.
  • Non-privileged role — the app connects as a role that cannot bypass RLS, with the tenant pinned per transaction.
  • No cross-tenant read — even a bug in application code cannot return another tenant's rows; the database refuses them.

03 · Keys & data residency

Three tiers. Know which one you're on.

Where your bid data physically sits is decided by your tier — not by a setting. We publish the ladder rather than let you assume, because a security review will find the answer anyway.

  1. Cloud

    EU-hosted — the standard plan

    Starter, Pro and Agency run on our shared platform in Frankfurt (EU). Tenant-isolated by PostgreSQL row-level security, human-approved, and never used to train models. This tier is not in-region for the Gulf, and it does not offer zero egress.

  2. Dedicated

    Single-tenant in the UAE

    A dedicated single-tenant deployment in AWS me-central-1, provisioned on signed demand. Worth being precise here: Saudi law does not require in-Kingdom hosting for private commercial data — the NCA removed that control in ECC-2:2024, and both Saudi and UAE PDPL permit cross-border transfer under standard contractual clauses. Choose this tier for procurement preference, a contractual residency clause, or government and critical-infrastructure work where in-Kingdom operation still binds. Priced above Agency.

  3. Sovereign

    On-prem, inside your network

    The on-prem edition runs entirely on your own infrastructure. This is the only tier with genuine zero egress — no prompt, document or price leaves your network, because nothing of ours is running outside it.

Secrets stay out of the database

Cloud provider API keys are read from your environment or secret store and never written to the application database — a leaked backup never yields a usable key.

Deploy where you must

Run EstiWright on-prem, in your own cloud account, or your VPC. The platform doesn't require a managed multi-tenant host you don't control.

In-region on request

The standard plan is EU-hosted. For UAE/KSA residency, the dedicated tier runs single-tenant in AWS me-central-1.

04 · Access, approvals & audit

Every action has an owner and a record.

  1. Identity

    SSO or signed tokens

    Single sign-on (Wright ID) or short-lived signed tokens — access and refresh tokens are separate and type-checked, so one can't stand in for the other.

  2. Roles

    Least-privilege access

    Super-admin, local-admin, engineer and viewer roles, with guardrails that stop a tenant from ever locking itself out of its own administration.

  3. Approvals

    Human-in-the-loop

    The AI drafts requirements, compliance positions and proposals; a person approves each one. Every sign-off is timestamped and attributable.

  4. Audit

    Append-only trail

    AI calls, approvals and configuration changes are logged to an append-only record — it can be read and added to, never quietly rewritten.

  5. Governance

    Spend you control

    Per-department and per-model metering, soft alerts, and hard budgets that refuse further spend when a ceiling is reached — fail loud, bill visibly.

  6. Evidence

    Defensible outputs

    Because the pipeline is deterministic and every position is signed off, a proposal comes with the trail that produced it — not an unexplained AI answer.

05 · What we don't do

Just as important as what we do.

We don't train on your data

Your tenders, requirements and pricing are never used to train models.

We don't share your tenders

Bid data isn't sold, brokered, or handed to third parties. It's yours.

We don't force egress

In on-prem mode, using EstiWright never requires your data to leave your network.

Have a security questionnaire?

Send it. We'll answer against the actual architecture — not a brochure. Formal attestations are on our roadmap; today we'll walk your team through the design, the deployment model, and how it maps to your controls.