eSourcingData - Source-to-Contract Procurement Software
Security · UK Data · Public Sector Ready

Due diligence documentation for IT, legal and procurement teams.

UK public bodies, NHS trusts, central government, housing associations and enterprise buyers all require robust security and compliance credentials before agreeing to a pilot or purchase. This page provides the information your IT, legal and procurement teams need in one place, no NDA required.

For additional documentation - penetration test reports, data processing agreements, security questionnaire responses, Cyber Assessment Framework (CAF) mappings - contact us directly. Most security packs returned within 5 working days.

Request security documentation

Cyber Essentials Plus

In progress

ISO 27001

Roadmap 2026

GDPR Compliant

ICO registered

UK Data Residency

All data UK-hosted

PA23 Ready

Full Act coverage

Audit-ready

Full evidence pack

Platform security

Architecture and data protection

Data residency

All data stored on UK-based servers

No data transferred outside the UK or EEA

Data centre locations: London and Manchester

Redundant storage with automatic failover

Encryption

All data encrypted at rest (AES-256)

All data encrypted in transit (TLS 1.3)

Evaluation scores and tender documents encrypted at row level

Supplier submission data isolated per procurement

Access control

Role-based access control throughout

Multi-factor authentication available

Session management with automatic timeout

Full user activity logging per organisation

Infrastructure

Hosted on enterprise-grade cloud infrastructure

99.9% uptime SLA

Automated daily backups with 30-day retention

Disaster recovery with 4-hour RTO

Penetration testing

Annual penetration testing by qualified third party

Most recent test: available on request

Critical findings: zero in last assessment

Vulnerability disclosure policy in place

Incident response

Documented incident response procedure

72-hour breach notification (GDPR compliant)

Designated Data Protection contact

ICO registration confirmed

Procurement Act 2023 compliance

How eSourcingData addresses every PA23 obligation

Every requirement listed below is built into the workflow - not a manual checklist.

Pipeline Notices (contracts over £2M)

Automated - system prompts at correct threshold, generates and publishes to FTS

Tender Notice publication on Find a Tender

Automated - published simultaneously with portal release, no manual FTS submission

Contracts Finder publication

Automated - all above-threshold contracts published automatically

Competitive Flexible Procedure

Supported - configurable multi-stage workflows with negotiation and presentation stages

Transparency Notices (modifications, terminations)

Prompted - system flags when a transparency notice is required and generates draft

Award Notice within 30 days

Automated - draft generated on award decision, published after standstill

Standstill period (8 working days)

Automated - clock started, all suppliers notified, contract execution blocked until expiry

Debrief letters to unsuccessful suppliers

Generated - templated debrief letters with score breakdown, sent automatically

Social value in selection criteria

Built in - configurable social value weighting in evaluation, delivery tracking post-award

Conflict of interest declarations

Built in - evaluators declare conflicts before accessing submissions

Procurement monitoring obligations

Dashboard - portfolio view with status, deadlines and compliance flags

Document retention (7 years)

Automated - all records retained with immutable audit trail, exportable on request

Multi-portal publication

Automated - notices published simultaneously to Find a Tender, Contracts Finder and Sell2Wales

Social value capture & reporting

Built in - community benefits, fair work, SME participation and carbon tracked notice-to-delivery

Conflict of interest gate

Enforced - declarations captured before submission access is granted

Audit & scrutiny pack

One-click - cabinet, board and audit review-ready reports from live data

GDPR & data processing

Data protection by design

Lawful basis

All personal data processing is conducted on a lawful basis under UK GDPR. Processing activities are documented in our Record of Processing Activities (ROPA). Available on request.

Data subject rights

We support all data subject rights: access, rectification, erasure, restriction, portability and objection. Requests are responded to within 30 days. Contact info@esourcingdata.com.

Data processors

All sub-processors are documented, EU/UK adequacy decision covered, and subject to data processing agreements. Processor list available on request.

Breach notification

We have documented procedures to detect, report and investigate breaches. ICO notification within 72 hours where required. Affected individuals notified without undue delay.

Need documentation for your IT or legal team?

We provide security questionnaire responses, data processing agreements, penetration test summaries and architecture documentation on request.

Request documentation

Procurement systems hold some of the most commercially sensitive information a public body will ever handle: unopened tenders, pricing models, evaluator scores, moderation notes and supplier assurance evidence. Get the controls wrong and you risk an unfair advantage, a leak, a challenge or a personal data breach. This page sets out how procurement data should be protected in practice, what the law expects under UK GDPR and the Procurement Act 2023, and the questions a buyer should put to any supplier before signing.

What procurement security actually has to protect

Security in procurement is not a single control. It is the combination of confidentiality before tender opening, integrity of the record afterwards, and availability when a deadline is fixed and cannot move. A tender box that leaks early is a fairness problem. A scoring record that can be quietly edited is an evidential problem. A platform that is unavailable on the day a submission closes is a legal problem, because suppliers who could not submit have a genuine grievance and the authority has to decide whether to extend.

The information at risk falls into three broad groups. There is personal data, such as named contacts, CVs, references and sometimes special category data in social value or safeguarding evidence. There is commercially sensitive supplier information, including rates, margins, methods and subcontracting arrangements. And there is the authority's own material, such as budget envelopes, internal benchmarks and evaluation guidance, which would distort a competition if it reached the market early.

Each group needs a different answer. Personal data is governed by UK GDPR and needs lawful basis, minimisation and retention discipline. Commercially sensitive data needs access control and sealed handling until the right moment. Authority material needs internal segregation, because the risk is usually an internal recipient rather than an external attacker. A credible platform treats these as separate problems rather than assuming one permission model covers all three.

UK data residency and where your data actually sits

eSourcing Data operates with UK data residency: procurement records, submissions and attachments are held in the United Kingdom. That matters for public sector buyers because many internal policies, and most information governance panels, start from a residency question before they look at anything else. It also simplifies the international transfer analysis, because if the data does not leave the UK there is no transfer mechanism to justify for the core service.

Residency is not the same as sovereignty, and buyers should ask about both. Where is the primary data stored, where are backups stored, and where is support delivered from? Remote administrative access from outside the UK is still a transfer of data in practice even when the storage location never changes. Ask for a straight answer on support locations, subprocessor locations and whether any analytics, logging or email delivery routes data outside the UK.

The same question applies to anything you bolt on. Document translation, virus scanning, e-signature, artificial intelligence assistance and even calendar invitations can quietly move content elsewhere. Keep a register of the components in use and check it when the service changes, rather than treating the answer given at procurement as permanent.

  • Where is live data stored, and in which country are backups held?
  • Which subprocessors are used, and what does each one see?
  • Is administrative or support access ever performed from outside the UK?
  • Do notifications, logs or analytics carry content or only metadata?

UK GDPR: lawful basis, minimisation and retention

For a contracting authority running a competition, the usual lawful basis for processing supplier contact and bid data is public task, or contract where the processing relates to a contract with the supplier. Consent is rarely the right basis, because a supplier cannot meaningfully refuse if refusal means exclusion. Record the basis you rely on in your privacy information and be consistent with it. If you rely on public task, say what function it relates to, because that is what regulators ask first.

Minimisation is where most procurement processes fail. Standard questionnaires often ask for named individuals, dates of birth, insurance certificates naming staff, or full CVs when a role profile would do. Ask whether you need the person or only the capability. If you do need named staff, ask at the right stage rather than collecting the whole market's personnel data at expression of interest. Less data collected is less data to protect, redact and eventually delete.

Retention should be tied to a purpose, not to a hard drive filling up. Award records, evaluation notes and the audit trail need to survive the standstill period and any limitation window for a challenge, and often longer for public accountability, contract management and audit. Unsuccessful bidders' commercial detail rarely needs to live that long in an accessible form. A defensible approach sets a schedule, applies it automatically, and records what was deleted and when.

Access control, roles and separation of duties in evaluation

Evaluation integrity depends on people seeing the right thing at the right time and nothing more. That means role based access rather than a shared login, and it means the platform enforcing separation rather than relying on a colleague's discretion. Evaluators should see the responses they are scoring. They should not see pricing during a quality evaluation if your method requires quality to be scored blind. Moderators need to see individual scores. Observers should be able to watch without touching.

Separation of duties also protects the people involved. If one person can open the tender box, assign evaluators, change a score and publish an award, then any allegation of manipulation is difficult to rebut. Split those permissions and the record itself becomes your defence. The same logic applies to conflicts of interest: declarations should be captured in the system, tied to the specific procurement, and enforced by removing access rather than by an instruction to look away.

Practical controls to check include single sign on with your identity provider, multi factor authentication for privileged users, timed access that expires at the end of a competition, and an administrator role that can grant access but cannot silently read sealed submissions. Ask how joiners, movers and leavers are handled, because stale accounts are the most common real world weakness in procurement systems.

  • Named accounts only, with no shared credentials for evaluation panels
  • Sealed tender box until the published deadline, with opening logged
  • Conflict declarations captured per procurement and enforced by access
  • Immediate removal of access when staff move roles or leave

Audit trails and the evidential record under the Procurement Act 2023

The Procurement Act 2023 came into force on 24 February 2025 and raised the bar for transparency across the whole commercial lifecycle, from planned procurement notices through to contract performance. Transparency only works if the underlying record is trustworthy. If an authority publishes an award decision, it needs to be able to show how the decision was reached, by whom, against the criteria it published, and that nothing changed afterwards without a visible reason.

That means the audit trail is not an administrative extra. It is the evidence you will rely on if a supplier challenges. A useful trail captures who accessed what and when, when the tender box was opened, individual scores before moderation, the moderated outcome with rationale, any score change with the reason recorded, clarification questions and answers issued to all bidders, and the exact documents each supplier received. Entries should be append only, so a correction adds a record rather than overwriting one.

Assessment summaries and standstill correspondence draw directly on this material. If your evaluation notes are thin, or exist only in a spreadsheet on someone's desktop, you are exposed twice: once because the feedback is weak, and again because the record cannot be shown to be complete. Keeping the whole process in one system, with time stamps generated by the system rather than typed by a person, removes most of that risk.

Encryption, backup, continuity and recovery

Encryption in transit and at rest should be a given rather than a selling point. Look for current transport security on every connection including file uploads, encryption of stored documents and database content, and sensible key management where keys are rotated and are not held alongside the data they protect. Ask specifically about attachments, because bid documents are often the largest and most sensitive part of the record and are sometimes handled by a different storage path from the structured data.

Continuity is where procurement differs from ordinary business software. Deadlines are legally significant. A recovery plan that restores service the next working day is not adequate when a competition closes at midday. Ask for the recovery time and recovery point objectives in writing, how often failover is tested, and what the supplier's documented process is if an outage prevents submissions. Also ask what the authority is expected to do, because extending a deadline is your decision and needs to be evidenced.

Backups need the same scrutiny as live data. Confirm frequency, retention, residency, encryption and, most importantly, whether restores are actually tested. A backup that has never been restored is an assumption. It is also worth asking how you get your data out at the end of the contract, in what format, and how deletion is confirmed, because exit is a security control as much as a commercial one.

Supplier and third party data handling

Where a platform processes personal data on your behalf it acts as a processor and you remain the controller. That relationship needs written terms covering the subject matter and duration of processing, the types of data and categories of individual, obligations of confidentiality, security measures, subprocessor approval, assistance with individual rights requests, breach notification timescales and deletion or return at the end. Check that the notification window is short enough to let you meet your own reporting obligations rather than consuming all of them.

Supplier assurance runs in the other direction too. Onboarding often collects insurance certificates, policies, accounts, health and safety records and details of subcontractors. That evidence should be held once, reused across competitions, and given an expiry date so it is refreshed rather than silently ageing. Suppliers benefit because they stop resubmitting the same documents. Buyers benefit because the assurance position is current, visible and evidenced rather than assembled from email attachments.

Subcontracting deserves particular attention. Ask suppliers who else will touch the data, where, and under what terms, and make sure your contract flows the obligations down. Under the Procurement Act 2023 regime there is far more emphasis on visibility of the supply chain and on contract performance, so knowing who actually delivers is both a security question and a compliance one.

Protecting sensitive commercial information during evaluation and moderation

The riskiest window in any competition is between the deadline and the award decision. Submissions are open, evaluators are reading detailed method statements, and pricing is in the room. Leaks at this stage are usually accidental: a document forwarded to a colleague, a spreadsheet of scores emailed for convenience, a moderation meeting held over a channel that keeps a copy elsewhere. The fix is to make the compliant route the easy one, so that no one needs to improvise.

Keep scoring and moderation inside the system. Individual scores should be recorded before moderation and preserved afterwards, so the moderated position is visibly a reasoned outcome rather than a rewrite. Comments should be written as if a supplier will read them, because in feedback they effectively will. Where a score changes at moderation, capture the reason at the moment of change rather than reconstructing it later.

Redaction matters at the other end. Transparency notices, freedom of information requests and assessment summaries all involve publishing or disclosing material that may contain third party commercial information. Handle redaction on a copy, keep the unredacted original intact in the record, and record who approved the disclosure. Confidentiality claims made by suppliers should be captured at submission so you are not chasing them under a statutory deadline.

Buying through G-Cloud 15 and Dynamic Markets: what still needs assessing

eSourcing Data software is available to public buyers through RM1557.15 G-Cloud 15, with 28 software services listed on the Digital Marketplace alongside cloud support services. Buying through a framework speeds up the commercial route because purchases are made as call off contracts under standard framework terms. It does not, however, do your information governance for you. The framework establishes the contractual scaffolding. The specifics of residency, subprocessors, retention and continuity still need to be confirmed for the service you are actually buying.

In practice that means reading the service definition and the supplier's published service description alongside your own requirements, then recording the assessment. Ask for the processing terms, the security overview and the exit provisions before the call off is signed, not afterwards. If your organisation has a data protection impact assessment threshold, a new procurement platform will usually cross it, and the assessment is far easier to complete while you still have the supplier's attention.

The same discipline applies to Dynamic Markets. Under the Procurement Act 2023 these replaced dynamic purchasing systems, and they are permanently open, cannot cap membership, and require applications to be assessed within a reasonable time, including pending applications before a competition concludes. That openness is a security design point: membership data, application evidence and assessment decisions all need controlled access and a clear record, because the market is continuous and applicants can challenge a refusal at any time.

A practical due diligence checklist for any supplier security review

A useful review asks for evidence rather than adjectives. Statements about being secure are not assessable. Ask instead for documents you can read, controls you can test in a trial environment, and commitments you can put in the contract. If a supplier cannot describe its own access model in plain English, that is itself a finding. Keep the review proportionate to the sensitivity of the data and the criticality of the deadline.

Record the answers, note anything the supplier could not evidence, and decide whether the gap is acceptable with a mitigation or whether it is a blocker. Then revisit the review at renewal, because architecture, subprocessors and support arrangements change over the life of a contract more often than buyers expect.

  • Where is data stored, backed up and supported from, and by whom?
  • What are the processor terms, and how quickly are breaches notified?
  • How is access controlled, and can privileged users read sealed submissions?
  • Is the audit trail append only, and can it be exported as evidence?
  • What are the tested recovery objectives, and what happens to a live deadline during an outage?
  • How is data returned and deleted at exit, in what format and on what timescale?
  • Which subprocessors are involved, and how are changes notified and approved?
  • How are joiners, movers and leavers handled on both sides?

Frequently asked questions

Is eSourcing Data hosted in the UK?

Yes. eSourcing Data operates with UK data residency, so procurement records, submissions and attachments are held in the United Kingdom. When you assess any platform, ask separately about backup locations and where support and administrative access are performed from, because those can differ from the primary storage location and are often the point that information governance panels focus on.

What is the lawful basis for processing supplier data in a tender?

Contracting authorities usually rely on public task for running a competition, or on contract where the processing relates to a contract with the supplier. Consent is rarely appropriate, because a supplier cannot freely refuse if refusal means exclusion. Record the basis in your privacy information, keep it consistent across the process, and be able to point to the function it supports.

How long should we keep tender documents and evaluation records?

Long enough to cover standstill, any challenge window, audit and contract management, which usually means award and evaluation records survive well beyond the competition. Unsuccessful bidders' detailed commercial material rarely needs to remain accessible for the same period. Set a retention schedule tied to purpose, apply it automatically, and keep a record of what was deleted and when.

What audit trail do we need for a Procurement Act 2023 challenge?

You need to show how the decision was reached: who accessed what and when, when the tender box was opened, individual scores before moderation, the moderated outcome and its rationale, any score change with a recorded reason, clarifications issued to all bidders, and the documents each supplier received. Entries should be append only, with system generated time stamps rather than typed ones.

Does buying through G-Cloud 15 cover our security assessment?

No. G-Cloud 15 gives you a fast commercial route, with purchases made as call off contracts under standard framework terms, but the framework does not replace your own information governance work. Confirm residency, subprocessors, processing terms, retention, continuity and exit for the specific service before the call off is signed, and complete a data protection impact assessment if your threshold is met.

How do you stop evaluators seeing pricing during a quality evaluation?

Through role based access enforced by the system rather than by instruction. Quality evaluators are given access only to the responses they are scoring, with pricing withheld until quality scoring is complete if your method requires that. Individual scores are recorded before moderation, and any change at moderation is logged with a reason, so the separation is evidenced rather than asserted.

What happens if the platform is unavailable on a submission deadline?

Ask any supplier for its documented process and its tested recovery objectives before you buy. Recovery targets measured in days are not adequate for procurement, because deadlines are legally significant. Extending a deadline remains the authority's decision, so make sure you can evidence the outage, the suppliers affected and the reasoning behind whatever extension or alternative arrangement you put in place.

How is supplier assurance evidence handled and kept current?

Assurance documents such as insurance, policies and accounts should be collected once, held against the supplier record and reused across competitions, with expiry dates that prompt refresh rather than letting evidence age quietly. That reduces duplication for suppliers and gives buyers a current, evidenced position instead of a folder of email attachments assembled during each individual procurement.

Do Dynamic Markets change how we handle applicant data?

They change the tempo. Dynamic Markets are permanently open, membership cannot be capped, applications must be assessed within a reasonable time, and pending applications must be considered before a competition concludes. That means membership data and assessment decisions are being created continuously, so access control, retention and a clear record of refusals matter throughout the life of the market rather than only at a single opening round.

Further reading

Dynamic Markets under the Procurement Act 2023G-Cloud 15: buying eSourcing Data softwareG-Cloud 15 service directoryProcurement Library: guidance, PPNs and playbooksFor buyers: source to contractProcurement Act 2023 readiness checkerBook a demonstration