Security
Last updated 11 August 2026
What we will never ask you for
- • Your digital signature certificate. Not the file, not the token, not the PIN.
- • Your password for any government e-procurement portal.
- • Your net-banking credentials, card PIN, CVV or any OTP.
- • If anyone asks you for these in our name, it is not us. Report it and we will act on it.
1. The DSC rule
A digital signature certificate is a legal instrument. Whoever holds it can bind your company. For that reason Avsar is built so that it never needs one: we prepare the bid pack, check eligibility and track deadlines, and the final upload happens on the government portal, performed by your own authorised signatory, with their own certificate, on their own machine.
This is a design constraint, not a feature we have not got to yet. We do not plan to add auto-submission, because the only way to build it is to hold something we should not hold.
2. Protecting your data
- All traffic is served over TLS. We do not accept unencrypted connections.
- Data is encrypted at rest, including vault documents.
- Workspaces are isolated. Your Company DNA, documents, pipeline and EMD register are visible only to users you have invited to your workspace.
- Access to production data is limited to the few people who need it to operate the service, and is logged.
- Backups are encrypted and restore procedures are tested.
3. What we hold, and what we do not
We hold what the product needs to work: your company profile, the documents you upload to the vault, your saved searches, your bid pipeline and your EMD register. We do not hold your DSC, portal credentials or payment instrument details. Card payments are processed by our payment gateway; card numbers never reach our servers.
4. Access control inside your team
Roles limit what each person can see and do. An owner can change Company DNA and billing; a bid manager can move the pipeline and generate packs; a finance user sees the treasury; a viewer is read-only. Remove a user from Settings and their access ends immediately.
5. Phishing and impersonation
Tender bidding attracts fraud, so be specific about what is normal. Avsar communicates from addresses at our own domain. We will never call or message you asking for a password, an OTP, a DSC token PIN, or a payment to an individual's account to “release” a tender or a refund. No government department does this either. If you receive such a message, tell us and do not act on it.
6. Reporting a vulnerability
If you believe you have found a security issue, write to us through our contact page with enough detail to reproduce it. We acknowledge reports within one working day and will keep you informed while we fix it. We will not pursue legal action against anyone who reports a genuine issue in good faith, tests only against their own account, and gives us a reasonable window before disclosing publicly.
7. Incidents
If a breach affecting personal data occurs, we will notify affected workspace owners without undue delay, describe what happened and what data was involved, and say what we are doing about it. We would rather tell you early and imprecisely than late and neatly.
8. Your part
- Use a password unique to this account.
- Invite team members individually rather than sharing one login.
- Remove people from Settings the day they leave.
- Keep your DSC token physically secure. It is the one thing we cannot protect for you.
9. Related policies
This page sits alongside our Privacy Policy, which sets out what we collect and how long we keep it, and our Terms of Service.