Hosting and encryption
- Application data is stored in Supabase (PostgreSQL) hosted on AWS in the United States. The web application runs on Vercel.
- All traffic is encrypted in transit with TLS; HSTS is enforced.
- Data is encrypted at rest by our hosting providers (AES-256).
- Database access is governed by row-level security policies — users can only read records their account is authorized to see.
- Payment card data is handled entirely by Stripe and never touches SamMatch servers.
How AI processes your RFP text
- Requirement Assist sends the solicitation text you paste or upload to the Google Gemini API to extract draft fields (PIID, NAICS, goal percentages, source snippet).
- Under Google's paid Gemini API terms, submitted content is not used to train Google's models.
- Extraction runs only when you initiate it. Nothing is auto-posted — your team reviews and attests every extracted field before a requirement goes live.
- If you prefer not to use AI processing, you can enter requirement fields manually; matching works identically.
What you must not upload
SamMatch is not authorized to process classified information, export-controlled technical data (ITAR/EAR), or Controlled Unclassified Information (CUI) that requires protection under FAR 52.204-21 / DFARS 252.204-7012. Upload only publicly releasable solicitation text or content your organization is authorized to share with commercial services. See our Terms of Service for details.
Retention and deletion
- Requirement drafts, messages, and outreach logs are retained while your account is active — they are your good-faith-effort record.
- You can archive requirements at any time. To permanently delete uploaded RFP text, a requirement, or your entire account, email support@sammatch.com — we process deletion requests within 30 days.
- Directory listings sourced from public SAM.gov and SBA records remain in the pool; claimed-profile data added by your company is removed on request.
Subprocessors
SamMatch relies on the following service providers to operate:
- Supabase — Application database, authentication, and file storage (hosted on AWS, US region)
- Vercel — Web application hosting and content delivery
- Stripe — Payment processing — card data never touches SamMatch servers
- Google (Gemini API) — AI field extraction from solicitation text you submit to Requirement Assist
- Resend — Transactional email delivery (alerts, magic links, solicitations)
- Sentry — Error monitoring — stack traces, not document contents
Access controls and monitoring
- Passwordless magic-link authentication — no passwords to leak or reuse.
- Team workspaces use per-seat accounts with role separation; no shared logins.
- Rate limiting and abuse controls on authentication and messaging endpoints.
- Error and availability monitoring with alerting on production incidents.
Compliance roadmap
SamMatch does not currently hold a SOC 2 attestation. As enterprise adoption grows we plan to pursue SOC 2 Type II. Customers who require a data-processing agreement, security questionnaire responses, or contractual terms can contact support@sammatch.com.
SamMatch is a private service and is not affiliated with, endorsed by, or operated by SAM.gov, the SBA, or any U.S. government agency.