Skip to content

Legal

Security

Captivaq holds proposal drafts, pricing approach and past performance, which is the most sensitive material a contractor owns. This page says how that is protected, in terms your security reviewer can check. It also says, in section 9, what we do not have yet.

Effective . Logesta Labs LLC operates Captivaq.

1. What we hold, and why it matters

Captivaq holds the most competitively sensitive material a contractor owns: capability statements, past performance records, personnel resumes, clearance levels, pricing approach and proposal drafts in progress. A competitor who read one workspace would learn more than they could from any public dataset.

So the controls below are built around one question. If an account is compromised, or an employee is careless, or a bug ships, what stops the damage from crossing between customers? Each section answers a piece of that.

2. Tenant isolation

A workspace is the boundary. Every record in the product hangs off a company profile, and every company profile hangs off a workspace. The API resolves the caller’s workspace from their session on the server, then constrains the query to it. A workspace identifier is never accepted from the client as the thing that decides what gets returned.

The same rule holds for the parts of the product that span several records. Pursuits, notes, tasks, watch lists, outcomes and the activity feed all resolve the full set of company entities a workspace owns and authorise against that set, so adding or switching an entity cannot widen what a member can reach.

Uploaded files follow it too. Object keys are built on the server from the workspace identifier, never from anything the browser sends, so one workspace cannot name another workspace’s folder.

3. How people sign in

There is no password to steal. The production application does not offer password sign-in at all. You sign in with a single-use link sent to your email address, or with your Google account, or through your own identity provider.

  • Sign-in links expire five minutes after they are sent, are single use, and are stored only as a hash, so the link in your inbox does not exist in readable form in our database.
  • Requests for a sign-in link are rate limited per address, and the tally is shared across every server instance rather than counted in one process's memory.
  • Google sign-in receives your name, email and profile picture, and nothing else. Accounts only link when the email addresses match.
  • Single sign-on through your own SAML or OIDC provider is available for enterprise workspaces. Arriving from a verified identity provider does not by itself grant access to a workspace: a person still has to be invited. A verified domain implying membership is how one customer's employee ends up in another customer's data.
  • Sessions are recorded in our database rather than only in a token, so they can be revoked, and they expire on their own.

4. What each person in a workspace can do

Roles are not advisory labels. The product declares a permission matrix in one file and enforces it on the server at every mutation, so the answer to “who can do this” is the same wherever the question is asked.

  • Owner: everything, including the plan, the payment method and handing the workspace over.
  • Admin: members, company entities, the company profile, API keys, and all capture work.
  • Member: the work itself. Notes, tasks, watching, pipeline moves and bid drafting. A member cannot change what the workspace is or what it costs.

A person can hold more than one role, and a permission is granted if any role they hold grants it. People named on the work, such as a task assignee, a capture manager or a gate reviewer, are validated against active workspace membership at the point of assignment, so removing someone from the workspace cannot leave them attached to a pursuit.

5. Encryption

Traffic to captivaq.com and app.captivaq.com runs over TLS, and the application is served over HTTPS only. Data is encrypted at rest by our database and object storage providers. Uploads and downloads use expiring presigned URLs issued by the server, so file bytes travel directly between your browser and the storage provider without passing through the application server.

6. The audit trail

Every action a person takes and every action an agent takes is written to one append-only stream. It records who acted, what they did, which record it touched, the fields before and after, where the action came from, and when.

It is written rather than derived. A feed reconstructed from timestamps can only show that a row changed; this one shows who changed it and to what. Rows are inserted and never edited, and the actor survives the user being deleted, so a departed employee’s history stays readable.

7. AI processing

Matching, summarising and drafting run on models operated by Google. The request carries the part of your content the feature needs and no more. Our agreement with the provider prohibits using your content to train its models, and we do not train models on your content either.

Solicitation documents come from the open internet, so the model is instructed to treat document contents as untrusted data and never as instructions. Extraction is constrained to a fixed output shape rather than free text, which limits what a poisoned document can cause the model to do.

One practical note that no control replaces. If a document is classified, export controlled, or under a non-disclosure agreement that forbids third-party processing, do not upload it.

8. API keys and machine access

API keys are minted by an owner or admin, shown once, and stored only as a hash. Each key carries explicit scopes rather than the rights of the person who created it, is rate limited, and can be revoked immediately. Key creation and revocation are recorded in the audit trail described in section 6.

9. What we do not have yet

Captivaq holds no third-party security certification today. No SOC 2, no ISO 27001, no FedRAMP authorisation, no DoD impact level. We have not completed an external penetration test.

We would rather say that here than let a procurement team discover it in week three of a review. If a certification is a condition of your purchase, tell us at contact@captivaq.com and we will tell you honestly whether the timeline works for you. When any of the above changes, it changes on this page first.

10. Where data lives, and who else touches it

The platform and every provider we use operate in the United States, and that is where your data is stored and processed. If you are in Canada, using Captivaq means your information is transferred to and held in the United States. The privacy policy covers what that means for you under PIPEDA and Quebec’s Law 25.

The current list of subprocessors, what each one does and what actually reaches them, is in section 7 of the privacy policy. It is one list, maintained in one place, and the data processing agreement incorporates it by reference rather than repeating it.

11. Deletion

You can close your account from the application without asking us. Doing so deletes the workspaces you alone own, so nothing is left behind that no one can reach. Content is deleted within 30 days and rolls out of encrypted backups within a further 90. Section 11 of the privacy policy gives the full schedule.

12. Reporting a vulnerability

Email contact@captivaq.com with the subject line “Security”. Tell us what you found, how to reproduce it, and how we can reach you. We aim to acknowledge within two business days.

We will not pursue legal action against anyone who reports a finding in good faith, gives us reasonable time to fix it, and does not access another customer’s data, degrade the service, or destroy anything along the way. There is no paid bounty today. If you believe an account or a document has already been exposed, say so in the first line and we will treat it as urgent.

Ask us about this

Questions about this page, a privacy request, or a security review from your team all reach the same inbox: contact@captivaq.com. Say which section you are asking about and we will answer it directly.