mytender.io Security Architecture: Enterprise-Grade Data Protection for Defense and Government Contractors
Four security tiers from fully managed cloud to completely isolated on-premise with Amazon Bedrock. Discover how mytender.io delivers flexible, defense-grade security for sensitive bid writing—with zero-training guarantees on all LLM calls.
mytender security team
mytender.io Security Architecture: Enterprise-Grade Data Protection for Defense and Government Contractors
For defense contractors, government agencies, and security-conscious enterprises, the question isn't whether to use AI for bid writing—it's whether AI can meet your stringent security requirements. At mytender.io, we've built a flexible security architecture that scales from secure cloud APIs to fully air-gapped deployments, ensuring your sensitive bid data remains protected at every level.
TL;DR:- Four security tiers to match your organisation's requirements—from fully managed to completely isolated
- Inference-only LLM calls: OpenAI, Anthropic, and Google never train on your data
- Complete isolation option: Amazon Bedrock ensures no data ever leaves your AWS environment
- Defense-ready: ITAR, NATO SECRET, and IL4+ compliant deployment options available
- Rapid deployment with white-glove implementation support
Security Architecture Overview
---
Understanding Your Security Options
mytender.io offers four distinct deployment tiers, allowing you to choose the security posture that matches your organisation's requirements. Each tier builds upon the previous, giving you progressively more control over where your data resides.
| Security Tier | Application Hosting | Database Hosting | LLM Processing | Best For |
|---|---|---|---|---|
| Tier 1: Fully Managed | mytender.io | mytender.io | External APIs (inference-only) | Commercial enterprises, non-classified bids |
| Tier 2: Client Database | mytender.io | Your infrastructure | External APIs (inference-only) | Data sovereignty requirements |
| Tier 3: Client Hosted | Your infrastructure | Your infrastructure | External APIs (inference-only) | Government contractors, sensitive data |
| Tier 4: Complete Isolation | Your infrastructure | Your infrastructure | Amazon Bedrock (your AWS) | Defense contractors, classified programs |
Tier 1: Fully Managed Cloud Deployment
Our default deployment option where mytender.io manages everything—application servers, database, and LLM integrations. This is the fastest way to get started while still maintaining enterprise-grade security.
What We Host
| Component | Managed By | Security Level |
|---|---|---|
| Frontend Application | mytender.io (AWS) | Enterprise-grade |
| Backend Services | mytender.io (AWS) | Enterprise-grade |
| Database (MongoDB) | mytender.io | Encrypted, isolated |
| LLM Processing | External APIs | Inference-only, no training |
How Your Data Is Protected
When using our fully managed deployment, your bid data is processed through leading LLM providers—OpenAI, Anthropic, and Google. It's essential to understand exactly how this works:
Your data is used for inference only. It is never used to train AI models.This isn't just our policy—it's contractually guaranteed by each provider:
| Provider | Training Policy | Data Retention | Contractual Guarantee |
|---|---|---|---|
| OpenAI | No training on API data | Zero retention on enterprise tier | Enterprise API ToS |
| Anthropic | Never trains on API inputs | Transient processing only | Commercial API Agreement |
| Google (Gemini) | No training on API requests | No persistent storage | Cloud API Terms |
What "Inference-Only" Means
When you submit a tender question to mytender.io:
- Your prompt is sent to the LLM provider via encrypted API call
- The model processes your request using its existing training
- A response is generated and returned to mytender.io
- The provider discards your data—it is not stored, logged for training, or used to improve their models
This is fundamentally different from consumer AI products (like ChatGPT's free tier), where conversations may be used for model improvement. Enterprise API access specifically excludes training on customer data.
Security Controls
Even in our fully managed tier, your data benefits from:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest
- SOC 2 Type II certified infrastructure
- GDPR and UK GDPR compliant data handling
- Role-based access control (RBAC) with granular permissions
- Complete audit logging for compliance requirements
---
Tier 2: Client-Hosted Database
For organisations requiring direct control over their data storage while leveraging mytender.io's managed application infrastructure.
Deployment Configuration
| Component | Hosted By | Your Control |
|---|---|---|
| Frontend Application | mytender.io | Managed for you |
| Backend Services | mytender.io | Managed for you |
| Database (MongoDB) | Your infrastructure | 100% control |
| LLM Processing | External APIs | Inference-only, no training |
Why Choose This Tier?
- Data sovereignty: Your bid documents and company data never leave your infrastructure
- Compliance requirements: Meet internal policies requiring database control
- Audit simplicity: Your security team has direct access to the database
- Reduced complexity: We still manage the application—you only manage the database
How It Works
- You deploy MongoDB Atlas (or self-hosted MongoDB) within your AWS/Azure VPC
- We configure secure connectivity via VPC peering or Private Link
- All bid documents, user data, and generated content are stored in your database
- Our application servers connect securely to query and update your data
- LLM API calls are made from our infrastructure (inference-only)
---
Tier 3: Fully Client-Hosted Application
For organisations requiring complete control over the application stack, mytender.io can be deployed entirely within your own cloud environment.
Complete Infrastructure Control
| Component | Hosted By | Your Control |
|---|---|---|
| Frontend Application | Your infrastructure | 100% control |
| Backend Services | Your infrastructure | 100% control |
| Database (MongoDB) | Your infrastructure | 100% control |
| Document Storage | Your infrastructure | 100% control |
| LLM Processing | External APIs | Inference-only, no training |
How Data Flows
- All bid documents remain in your infrastructure—never uploaded to mytender.io servers
- Only the specific prompt context (question + relevant excerpts) is sent to LLM APIs
- Full documents are never transmitted—we extract and send only what's needed for the query
- LLM responses return directly to your infrastructure
- Complete audit trail maintained within your environment
Architecture Overview
AWS Deployment:- Amazon ECS with Fargate (serverless, no EC2 instances to manage)
- Application Load Balancer with WAF protection
- MongoDB Atlas with VPC peering (private connectivity)
- AWS Secrets Manager for credential security
- CloudWatch for monitoring, CloudTrail for audit
- Azure Container Instances (serverless containers)
- Azure Application Gateway with WAF
- MongoDB Atlas with Private Link
- Azure Key Vault for secrets management
- Azure Monitor and Log Analytics for comprehensive visibility
The External API Question
In Tier 3, LLM API calls still go to external providers (OpenAI, Anthropic, Google). However:
- Only prompt context leaves your environment—never full documents
- All providers guarantee inference-only processing—no training on your data
- Encrypted transmission via TLS 1.3
- No data retention by any provider
For many government contractors and enterprises, this level of isolation is sufficient. For organisations that cannot allow any external API calls, Tier 4 provides complete isolation.
---
Tier 4: Complete Isolation with Amazon Bedrock
For defense contractors, classified programs, and organisations where absolutely no data can leave your AWS environment, Tier 4 provides complete isolation. Everything runs within your infrastructure—the application, the database, and the LLMs themselves.
What "Complete Isolation" Means
| Component | Hosted By | Your Control |
|---|---|---|
| Frontend Application | Your infrastructure | 100% control |
| Backend Services | Your infrastructure | 100% control |
| Database (MongoDB) | Your infrastructure | 100% control |
| Document Storage | Your infrastructure | 100% control |
| LLM Processing | Amazon Bedrock (your AWS account) | 100% control |
Zero External API Calls—Complete Data Isolation
With Amazon Bedrock integration, your deployment architecture changes fundamentally:
| Aspect | Tiers 1-3 (External LLM APIs) | Tier 4 (Amazon Bedrock) |
|---|---|---|
| Data leaves your AWS account | Yes (for inference only) | No—never |
| API calls cross the internet | Yes (encrypted) | No—VPC endpoints only |
| Third-party data processing | Yes (inference-only, no training) | No—AWS processes within your account |
| Model provider access to data | Transient only | None—models run in your environment |
How Amazon Bedrock Works
Amazon Bedrock provides access to foundation models from Anthropic (Claude), Meta (Llama), Amazon (Titan), and others—but with a critical difference: the models run within AWS infrastructure that you control.
Key Security Properties:- VPC Endpoints: All communication stays within your VPC via AWS PrivateLink
- No Internet Egress: Model inference happens without any external network calls
- AWS Responsibility: Processing occurs within AWS's secure infrastructure under your account
- Encryption: Your data is encrypted with keys you control (AWS KMS)
- Compliance Inheritance: Bedrock inherits AWS compliance certifications (FedRAMP High, IL5, etc.)
Performance Considerations
We believe in transparency. While Amazon Bedrock provides unmatched data isolation, there are trade-offs to consider:
| Factor | External APIs (OpenAI/Anthropic) | Amazon Bedrock |
|---|---|---|
| Model Selection | Latest models (GPT-4, Claude 3.5) | Bedrock-available models |
| Response Quality | State-of-the-art | Excellent (may vary by use case) |
| Latency | Optimized global infrastructure | Dependent on your AWS region |
| Cost | Pay-per-token | Pay-per-token + Bedrock pricing |
Fully Isolated Architecture
Your AWS Account contains everything:| Layer | Components | Connectivity |
|---|---|---|
| Application | Frontend (Amplify) + Backend (Fargate) | Internal VPC networking |
| Database | MongoDB Atlas | VPC peering / Private Link |
| AI Processing | Amazon Bedrock | VPC Endpoint (PrivateLink) |
- User accesses Frontend (within your VPC)
- Frontend calls Backend (within your VPC)
- Backend queries MongoDB (within your VPC)
- Backend calls Bedrock via VPC Endpoint (stays within AWS)
- Response returns through the same secure path
- No data leaves your AWS account
- No external API calls
- Complete audit trail in CloudTrail
---
Security Classifications and Compliance
Deployment Tier by Classification Level
| Classification | Tier 1 (Fully Managed) | Tier 2 (Client DB) | Tier 3 (Client Hosted) | Tier 4 (Bedrock) |
|---|---|---|---|---|
| Commercial Confidential | ✅ Recommended | ✅ Available | ✅ Available | ✅ Available |
| Government IL2 | ✅ Compliant | ✅ Compliant | ✅ Compliant | ✅ Compliant |
| Government IL4 | ⚠️ Case-by-case | ⚠️ Case-by-case | ✅ Compliant | ✅ Recommended |
| Government IL5 | ❌ Not suitable | ❌ Not suitable | ⚠️ Case-by-case | ✅ Recommended |
| ITAR Controlled | ❌ Not suitable | ❌ Not suitable | ⚠️ With controls | ✅ Recommended |
| NATO SECRET | ❌ Not suitable | ❌ Not suitable | ❌ Not suitable | ✅ With approval |
Compliance Frameworks Supported
Tier 4 (Amazon Bedrock) Deployments:- FedRAMP High (via AWS GovCloud option)
- ITAR (with appropriate AWS configuration)
- SOC 2 Type II
- ISO 27001, 27017, 27018
- HIPAA (for healthcare-adjacent bids)
- PCI DSS (where applicable)
---
Implementation Process
For Defense Contractors: White-Glove Deployment
We understand that defense contractors face unique challenges. Our implementation team includes personnel experienced with:
- ITAR compliance requirements
- Classified network architecture
- FedRAMP authorization processes
- Defense contractor security practices
Deployment Timeline
| Phase | Duration | Activities |
|---|---|---|
| Discovery | 1 week | Security requirements, compliance mapping, architecture design |
| Infrastructure | 1-2 weeks | VPC setup, container deployment, database configuration |
| Integration | 1 week | SSO integration, Bedrock configuration, security hardening |
| Validation | 1 week | Security testing, compliance verification, user acceptance |
---
Frequently Asked Questions
"Can OpenAI/Anthropic/Google see our bid data?"
With Tiers 1-3, the LLM provider processes your prompt to generate a response. However:
- They do not store your data beyond transient processing
- They do not use your data for training
- They do not have humans reviewing your queries
- Enterprise API agreements contractually prohibit training on your data
Only the specific prompt context is sent—never your full documents.
"What if we can't allow ANY external API calls?"
Choose Tier 4 with Amazon Bedrock. All LLM processing occurs within your AWS account via VPC endpoints. No data ever leaves your environment—not even transiently.
"Will quality suffer with Amazon Bedrock?"
Amazon Bedrock provides access to state-of-the-art models including Anthropic's Claude (the same model family used in our cloud deployment). We optimise our prompts specifically for Bedrock-available models, and most customers report equivalent quality for bid writing tasks. There may be minor differences in edge cases, but for the vast majority of bid writing tasks, quality is comparable.
"Can we switch tiers later?"
Yes. Our architecture supports seamless migration between tiers. Many customers start with Tier 1 for non-sensitive bids and use Tier 4 for classified programs, running both simultaneously.
"What's the difference between Tier 2 and Tier 3?"
- Tier 2: You host only the database; we manage the application
- Tier 3: You host both the database and the application
Both tiers still use external LLM APIs (inference-only). Choose Tier 2 if you want data sovereignty without managing application infrastructure. Choose Tier 3 if you need complete control over the entire stack.
"What about UK data sovereignty?"
For UK defense contractors, we offer:
- UK-based AWS regions (London eu-west-2)
- UK GDPR compliance built into all tiers
- UK-cleared implementation support available on request
---
Why Defense Contractors Choose mytender.io
- Four Security Tiers: From fully managed to completely isolated—match your deployment to your classification level
- Zero-Training Guarantee: Across all tiers, your data never trains AI models
- Progressive Control: Start with Tier 1 and migrate to Tier 4 as requirements evolve
- Complete Isolation Option: Tier 4 with Amazon Bedrock ensures nothing leaves your environment
- Rapid Deployment: Operational in weeks, not months
- Defense-Experienced Team: We understand ITAR, classified programs, and government contracting
- Proven Technology: Enterprise-grade infrastructure trusted by security-conscious organisations
---
Next Steps
Ready to discuss how mytender.io can support your defense or government contracting needs?
- Security Assessment: We'll review your specific requirements and recommend the appropriate tier
- Architecture Design: Custom deployment design for your AWS/Azure environment
- Compliance Mapping: Documentation for your security accreditation process
- Pilot Program: Test mytender.io with non-sensitive bids before full deployment
---
Your bid data deserves the same protection as your most sensitive programs. With mytender.io, you don't have to choose between AI capability and security compliance.Tags
Ready to Transform Your Tender Writing?
See how MyTender's AI can help you write winning tenders in a fraction of the time.
