Klimo AI LLC

Security and privacy

Capture holds your company’s bid profile. This page says exactly what that means: what we keep, what we refuse to keep, who can read it, and how to take it back. Updated 15 September 2026.

What we store

Solicitation documents you upload. These are public procurement records — the packet, its addenda, the forms. We keep the original file, the text we extracted from it, and a page map so every line in a brief can point at the page it came from.

Your Vault. Your company profile: legal identity and registration numbers, NAICS and NIGP codes, certifications, insurance types and limits, past performance, key personnel, capacity, and revenue history. This is the confidential part, and it is the part we design around.

The work. Briefs, compliance matrices, checklists, deadlines and the record of who exported or downloaded what.

What we never store

Where it lives

In the United States. The database and your files are in Supabase (US region), encrypted at rest; the API and background jobs run on Railway; this site is served by Vercel. Traffic is TLS 1.2 or better. Download links are signed and expire — five minutes for a document, 24 hours for an export you asked for.

Backups: daily backups of your database and uploaded files, 30-day retention.

Who can see it

Your company’s data is walled off in the database itself, not just in the interface. Every table carries a row-level policy that answers “nothing” to anyone outside your company, and a test suite proves it on every change by signing in as one company and asking for another’s rows.

Seats. An owner runs the company account. A member does the work. A counselor — your APEX or PTAC advisor — is read-only, cannot export anything, and cannot see revenue or insurance limits at all. That last part is enforced by the database, not by a hidden button.

Two-factor authentication is available on every account and required on Team accounts, which cannot be opened at all until a second factor has been used. Removing someone’s seat ends their session on their next request.

We log the sensitive reads. Every read of your revenue or insurance limits and every export is written to an audit trail with who did it and when.

The AI, and what it is allowed to keep

Capture uses Anthropic’s Claude API to read packets and to reason about fit. Anthropic is a subprocessor, and these are their commercial API terms as we verified them on 9 September 2026:

Default commercial API retention is 30 days, and retained data is never used for training.

We do not use the Batch API for your documents, and we never route them through a “Covered Model”. The service refuses to start if it is configured with one.

The caveat, stated rather than buried: Anthropic may retain data flagged by their automated trust and safety systems for up to two years, or where required by law. That applies even under zero-retention agreements.

On our side, no document text and no Vault text is ever written to a log. Our logs record the job, the model, the token count and the cost.

How long we keep it, and how to get it back

Retention. You can delete a packet, a Vault entry or your whole account whenever you like, and deletion is immediate rather than a request in a queue. Our own policy is to keep nothing longer than 12 months after a solicitation closes; the automatic sweep that enforces it is not built yet, so today that clean-up is ours to run by hand and yours to trigger at any time.

Export my data. From Settings, one click gives you a JSON file of every row your company owns and a ZIP of every file you uploaded, behind a link that expires in 24 hours.

Delete my account. Also one click, for an owner, confirmed by typing your company name. It removes your rows, the files in storage and any export artifacts within seven days. Delete means delete: we have a test that lists the storage folder afterwards and fails if anything is still there.

Where we stand on compliance

Not FedRAMP / TX-RAMP / StateRAMP — and doesn’t need to be: Capture never connects to a government system, never stores government data beyond public solicitations, and the government is never the customer. It is a vendor-side tool, like accounting software. If an agency ever wants to buy Capture directly, that is a separate product decision with a separate compliance path.

What Capture will not do

It does not submit anything, ever, and it never connects to a procurement portal. You download the packet, you upload it here, and a person on your side reviews, signs and submits. Capture is decision support: it does not guarantee an award, and every brief is built from facts that cite the page they came from so you can check them.

Who else touches the data

SubprocessorWhat it doesWhere
SupabaseDatabase, file storage, sign-inUnited States
AnthropicThe AI that reads your packetsUnited States
RailwayRuns the API and background jobsUnited States
VercelServes this websiteUnited States
ResendSends deadline emailsUnited States
TwilioSends deadline texts, if you turn them onUnited States
TelegramAlerts us when something breaks. No customer data.

A data processing agreement is available, and we will sign yours if your counsel prefers it.

Who built this

Klimo AI LLC is a Texas company, and its founder is a registered vendor on CMBL, SAM and Bonfire who has stood in the same portals this tool is built for. The rules above are the ones we wanted as a bidder.

Questions, or a security issue to report: security@klimo.ai.