TK
TenderKaki
Sign in Book a 15-minute demo
Security at TenderKaki

Your price data is your weapon. We guard it like one.

Your rates are the most sensitive thing a contractor owns. This page is the honest, plain-language version of how we protect them — including what we deliberately do not claim.

Book a 15-minute demo See plans & pricing
WhatsApp Only · +6016 468 8686
The question everyone asks first

“Can TenderKaki staff see my prices?”

The honest answer — the bank analogy

Think of a bank: staff cannot browse your account, but the bank’s system must process your money. TenderKaki works the same way.

Developer access is locked down and logged. Nobody at TenderKaki browses customer data as part of day-to-day work.
The system — including the AI — must read your files in order to parse them. Software that could not read your tender could not cost it.
Your data is never used to train AI.
Your data is never shared across companies — not with competitors, not with anyone.
The concrete promises

Seven promises. Each one is built into the product, not written into a policy.

Company-level isolation

Enforced at the database layer itself — not just in the app’s code.

Encrypted in transit and at rest

Your data is encrypted on the wire and in storage.

Full audit logs

Every AI suggestion and every human confirmation is logged — who, what, when.

Developer access locked and logged

Production access is restricted, audited, and never casual.

Customer data never trains AI

The AI reads your files only to make suggestions inside your account. AI suggests, your QS confirms.

Zero cross-company data sharing

No benchmarking pools, no “market rates” built from your library. Your rates stay yours.

The reference library is separate

The official reference rate library is founder-curated from industry-general Malaysian rates — structurally separate from customer data, and never derived from it.

How isolation works

The hotel keycard, in plain language.

Your company’s keycard opens only your company’s floor. The rule lives in the building itself — the database — not in the app remembering to check. Even if a screen in the app had a bug, the database would still refuse to hand over another company’s rows.

And we attack it ourselves: automated cross-company attack tests run on every single code change. If even one row could leak from one company to another, the build fails and cannot ship.
What we do not claim

We’d rather be honest than impressive.

Some products promise “zero-knowledge” security — meaning the service itself can never read your data. We deliberately do not make that claim, because for TenderKaki it cannot be true: to parse your tender files and suggest mappings and rates, the system and the AI must be able to read them. A platform that literally could not read your files could not do this work.

So instead of an impossible promise, we give you real ones: isolation enforced at the database layer, encryption everywhere, locked and logged access, full audit trails — and this page, written in plain language.

Your data is yours

In, out, or gone — you decide.

Export everything, anytime

Your projects export as real Excel with live formulas, and you can request a full export of your company’s data whenever you want it.

Downgrade or cancel — nothing is deleted

Cancelling moves you to the GO tier; every project, price and audit record stays exactly where it was. Your price library is never held hostage.

Deletion on request

If you ever want your company’s data gone, ask — and it will be deleted.

Security FAQ

Straight questions, straight answers.

Still have a security question? Ask the founder directly.

15 minutes on WhatsApp — bring your hardest question.

WhatsApp us — book a 15-minute demo Back to pricing
🇲🇾 WhatsApp Only · +6016 468 8686