Skip to main content
SamMatch

Security & data handling

Last updated: July 2026

SamMatch is a B2B compliance workspace for federal contracting teams. This page explains where your data lives, how it is protected, how AI processing works, and what controls you have. Questions we have not answered here: support@sammatch.com.

Hosting and encryption

  • Application data is stored in Supabase (PostgreSQL) hosted on AWS in the United States. The web application runs on Vercel.
  • All traffic is encrypted in transit with TLS; HSTS is enforced.
  • Data is encrypted at rest by our hosting providers (AES-256).
  • Database access is governed by row-level security policies — users can only read records their account is authorized to see.
  • Payment card data is handled entirely by Stripe and never touches SamMatch servers.

How AI processes your RFP text

  • Requirement Assist sends the solicitation text you paste or upload to the Google Gemini API to extract draft fields (PIID, NAICS, goal percentages, source snippet).
  • Under Google's paid Gemini API terms, submitted content is not used to train Google's models.
  • Extraction runs only when you initiate it. Nothing is auto-posted — your team reviews and attests every extracted field before a requirement goes live.
  • If you prefer not to use AI processing, you can enter requirement fields manually; matching works identically.

What you must not upload

SamMatch is not authorized to process classified information, export-controlled technical data (ITAR/EAR), or Controlled Unclassified Information (CUI) that requires protection under FAR 52.204-21 / DFARS 252.204-7012. Upload only publicly releasable solicitation text or content your organization is authorized to share with commercial services. See our Terms of Service for details.

Retention and deletion

  • Requirement drafts, messages, and outreach logs are retained while your account is active — they are your good-faith-effort record.
  • You can archive requirements at any time. To permanently delete uploaded RFP text, a requirement, or your entire account, email support@sammatch.com — we process deletion requests within 30 days.
  • Directory listings sourced from public SAM.gov and SBA records remain in the pool; claimed-profile data added by your company is removed on request.

Subprocessors

SamMatch relies on the following service providers to operate:

  • SupabaseApplication database, authentication, and file storage (hosted on AWS, US region)
  • VercelWeb application hosting and content delivery
  • StripePayment processing — card data never touches SamMatch servers
  • Google (Gemini API)AI field extraction from solicitation text you submit to Requirement Assist
  • ResendTransactional email delivery (alerts, magic links, solicitations)
  • SentryError monitoring — stack traces, not document contents

Access controls and monitoring

  • Passwordless magic-link authentication — no passwords to leak or reuse.
  • Team workspaces use per-seat accounts with role separation; no shared logins.
  • Rate limiting and abuse controls on authentication and messaging endpoints.
  • Error and availability monitoring with alerting on production incidents.

Compliance roadmap

SamMatch does not currently hold a SOC 2 attestation. As enterprise adoption grows we plan to pursue SOC 2 Type II. Customers who require a data-processing agreement, security questionnaire responses, or contractual terms can contact support@sammatch.com.

SamMatch is a private service and is not affiliated with, endorsed by, or operated by SAM.gov, the SBA, or any U.S. government agency.