Blog · 10 September 2026

Tender integrity needs proof, not another audit log

Sealed bidding is already a product category. Independently verifiable tender integrity is not. That gap is where we are building.

← All posts

What a tender is, and why it is hard to run well

A tender is a structured competition for a contract. The buyer publishes requirements and rules, suppliers submit priced offers by a deadline, and the buyer evaluates the offers under the published rules and awards. Public procurement, infrastructure, defence, energy, and large corporate sourcing all run on this pattern because it promises two things: the best offer wins, and every bidder was treated the same.

That promise is fragile, and the failure modes are old:

  • A bid leaks before the deadline and a competitor adjusts its price.
  • A late or altered bid slips into evaluation.
  • The rules or the scoring change after bids are in.
  • An insider with system access reads sealed offers early.
  • Losing bidders cannot tell whether the process was clean, so they challenge the award.

Paper procurement answered these with the sealed envelope: bids locked in a box, opened together in front of witnesses after the deadline. Crude, but the guarantee was structural. Nobody could read an envelope early without leaving marks.

What exists today

Electronic tendering replaced the envelope with platforms: Ariba, Coupa, Keelvar, Fairmarkit, and many public-sector portals. These systems encrypt stored bids, restrict who can open what and when, timestamp submissions, and retain audit logs. Procurement law expects this. Electronic submission rules in regimes such as EU Directive 2014/24/EU expect tenders to remain confidential until the deadline, to be opened only by authorised persons, and they contemplate encryption and time-stamping.

For routine sourcing, that stack is enough. The platforms are good at what they were built for: supplier discovery, event management, bid analysis, and award workflow.

The gap

Every one of those guarantees is an assertion by the platform operator. Encryption at rest, access control, and audit logs all reduce to the same statement: trust our administration. The operator holds the keys, administers the access rules, and writes the logs. When a bidder, an auditor, or a court asks the platform to prove that nobody could read the bids early, and that the evaluated bids are the same bytes the suppliers submitted, the honest answer is: here are our logs.

That is the gap. Sealed bidding is a product category. Independently verifiable tender integrity is not.

Current platforms give the buyer an audit log. They do not give any third party a way to prove, without trusting the platform operator, that the bids were sealed on the supplier side before the platform could read them, that no late or altered bid entered evaluation, and that the evaluated payloads are exactly the bytes the suppliers committed before the deadline.

One way to name the gap: access control says who may look. It does not, by itself, give a third party a way to check that nobody could look before the opening condition, or that the evaluated payload is the same bytes the supplier sealed.

The conventional path is:

Supplier → procurement platform → encrypted store → buyer → evaluation → award

A stronger model people keep proposing in different forms is:

Supplier → sealed bid + cryptographic commitment → platform → governed evaluation → independently checkable proof → award

The buyer still designs the event, validates structure, runs optimisation, and awards. The open design question is whether that proof layer sits inside the sourcing product, beside it, or only appears when a dispute starts. Building another full marketplace is a different question from binding the sensitive path so material claims about the process become checkable without the operator's word.

What “verified” has to mean

For a high-assurance sealed event, the useful claims are concrete:

  1. The tender rules and bid schema were committed before protected bidding opened.
  2. Commercial contents were sealed on the supplier side before buyer-accessible persistence.
  3. Revisions are chained; the operative pre-deadline bid is deterministic.
  4. Opening requires an authorised policy, ideally multi-party, not a single admin decrypt.
  5. Evaluated payloads match opened submissions; the published outcome corresponds to that set.

Stakeholders who need assurance (governance, auditors, contracting authorities, and sometimes unsuccessful bidders) should verify those claims without receiving losing prices, sensitive attachments, or trade secrets outside their entitlement.

One artefact shape worth debating is a compact integrity certificate: human-readable checks plus a cryptographic root, verifiable offline relative to the sealed values, without shipping losing prices or confidential attachments.

Open questions worth arguing about

If you run or buy high-stakes tenders, these are the questions the audit-log story still leaves open:

  1. When a losing bidder challenges an award, what can you show that does not depend on the platform operator's word?
  2. If an administrator with privileged access denies reading sealed bids early, how would an independent party know?
  3. Should "sealed until deadline" mean access control on a server the buyer controls, or a commitment the supplier formed before the platform ever held cleartext?
  4. For events that already demand multi-person opening ceremonies on paper, what is the electronic equivalent that outsiders can check?
  5. Where should the integrity layer live: inside the sourcing product as a premium path, beside it as a protected submission portal, or only in dispute after the fact?

Procurement law and institutional policy already speak the language of integrity and confidentiality. Cryptography does not make a process lawful by itself. It can only help evidence the properties those rules ask for.

There is also a product boundary worth stating clearly. Supplier networks, bid optimisation, and contract lifecycle tools are real markets with real incumbents. Rip-and-replace for the buyer's existing platform is a different bet. An integrity layer that sits under those surfaces is a narrower claim: the sealed path, the opening condition, and something a third party can verify without receiving confidential bid values.

We think that narrower claim is the missing compliance product. We would rather hear the counter-arguments from people who run these events than close the debate ourselves.

Continue the conversation

If you operate high-stakes RFx and the integrity questions above are live for you, we want that discussion.