SureLock OS

Privacy Policy

Effective date: June 2025

1. What We Collect

When you request access or use SureLock OS, we collect:

  • Name, company, email address, and role (from access requests)
  • Login credentials (passwords stored as bcrypt hashes — never in plaintext)
  • SAM.gov API keys you choose to store in your account settings
  • Opportunity data, supplier records, and workflow activity you create within the platform

2. How We Use It

Data you enter is used solely to operate SureLock OS for your account. We do not sell, share, or disclose your data to third parties except as required to operate the platform (e.g., SAM.gov API calls using your API key) or comply with law.

3. Data Storage

Your data is stored in Supabase, a managed PostgreSQL database hosted in the United States. All data is encrypted at rest and in transit. Row-level security (RLS) is enabled on all tables — your session credentials are required to access any data.

4. SAM.gov API Keys

If you store a SAM.gov API key in Settings, it is saved to your user record in our database and used exclusively to fetch opportunity data on your behalf. You can remove it at any time by overwriting it in Settings → Integrations.

5. Session Cookies

SureLock OS uses a single HttpOnly session cookie (sl_session) to maintain your login state. This cookie is not accessible to JavaScript and is automatically cleared when you sign out.

6. Your Rights

You may request deletion of your account and associated data at any time by contacting us. Account deletion is permanent and cannot be undone.

7. Changes

We may update this policy as the platform evolves. Material changes will be communicated to active users via the email address on file.

8. Contact

SureLock LLC · 636 Cherrywood Ln, Richland, WA 99354
Devin.Ayala@SureLockENT.com