Security Policy

Effective Date: July 23, 2026

This Security Policy describes the security practices followed by GarvFlow, an AI-powered Tender Analysis and Bid Management platform operated by Garv Nexus. Our goal is to protect customer information and maintain a secure platform for businesses using GarvFlow.

1. Our Commitment

GarvFlow is designed with security as a core principle.

We continuously work to protect customer data from unauthorized access, misuse, loss, alteration, and disclosure by implementing reasonable technical and organizational safeguards.

While no online system can guarantee absolute security, we strive to follow industry-standard security practices appropriate for our services.

2. Data Protection

GarvFlow processes business documents uploaded by customers, including tender-related files.

We implement reasonable safeguards to help protect customer data during storage and transmission. These safeguards may include:

  • Secure authentication mechanisms
  • Encrypted communication (HTTPS/TLS)
  • Access controls based on user permissions
  • Secure cloud infrastructure
  • Regular monitoring and logging where appropriate

3. Account Security

Users are responsible for maintaining the confidentiality of their login credentials.

We recommend that users:

  • Choose strong passwords.
  • Do not share account credentials.
  • Use unique passwords for GarvFlow.
  • Immediately notify us if unauthorized access is suspected.

GarvFlow is not responsible for security incidents resulting from compromised user credentials.

4. Document Security

Documents uploaded to GarvFlow are processed solely for providing platform services such as:

  • AI Tender Analysis
  • Eligibility Analysis
  • Risk Detection
  • Technical Bid Drafting
  • Financial Bid Drafting
  • Other requested AI-powered features

Uploaded documents remain the property of the customer. GarvFlow does not claim ownership of customer documents.

5. AI Processing

GarvFlow uses Artificial Intelligence to analyze uploaded documents. AI processing is performed only for the purpose of providing requested platform functionality.

Users should avoid uploading information they are not legally permitted to share.

6. Access Control

Access to customer information is restricted to authorized systems and, where necessary, authorized personnel for operational, maintenance, support, or security purposes.

Access is granted on a need-to-know basis.

7. Infrastructure Security

GarvFlow is designed to use modern cloud infrastructure and security best practices where applicable, including:

  • Secure hosting environments
  • Firewall protections where supported
  • Monitoring of platform health
  • Backup and recovery procedures where appropriate

Infrastructure providers may maintain their own independent security programs.

8. Third-Party Services

GarvFlow may rely on trusted third-party providers for services such as:

  • Cloud hosting
  • Authentication
  • Payment processing
  • Email delivery
  • Analytics
  • Artificial Intelligence services

These providers maintain their own security and privacy practices, which may be governed by separate policies.

9. Security Monitoring

We continuously work to identify and address potential security issues. This may include:

  • Monitoring unusual activity
  • Investigating reported vulnerabilities
  • Applying software updates
  • Improving security controls over time

10. Responsible Disclosure

If you believe you have discovered a security vulnerability in GarvFlow, please notify us promptly.

Please include:

  • Description of the issue
  • Steps to reproduce (if applicable)
  • Relevant screenshots or evidence
  • Contact information

Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to investigate and respond.

11. User Responsibilities

Users are responsible for:

  • Protecting their account credentials.
  • Uploading only documents they are authorized to use.
  • Reviewing AI-generated outputs before relying on them.
  • Keeping their own devices and browsers secure.
  • Using GarvFlow in accordance with applicable laws.

12. Service Availability

Although we strive to maintain high availability, GarvFlow cannot guarantee uninterrupted access.

Temporary interruptions may occur due to:

  • Maintenance
  • Infrastructure upgrades
  • Third-party service disruptions
  • Internet connectivity issues
  • Security incidents
  • Events beyond our reasonable control

13. Security Limitations

Despite reasonable safeguards, no software platform or internet-based service can guarantee complete protection against every possible security threat.

Users acknowledge these inherent risks when using online services.

14. Policy Updates

GarvFlow may update this Security Policy from time to time to reflect improvements in technology, security practices, or legal requirements.

The latest version will always be published on our official website.

15. Contact Us

For security-related questions or to report a potential security issue, please contact: