How sealed submission works
Version 2026-10-04
Your browser encrypts each file and your prices before upload, with a new key for every file. The key is locked with the tender's public key for that section. Our servers store only encrypted data.
Qualification, technical, financial and other parts are sealed separately, so a buyer can open prices later than the rest.
A bid counts when you press "Submit bid" and our database clock records the commit, before the deadline. The time is in your signed receipt.
You can replace or withdraw your bid until the deadline. Only the latest version is opened.
You confirm each submission, replacement and withdrawal with your Tendergate account. Some tenders also ask for your company's submission key, a passkey or an authenticator app: the tender page says so, and statutory procedures always do.
After the deadline, the buyer's appointed opener opens the bids, or two openers together where the buyer or the rules require it. Every opening is recorded in a log that cannot be changed.
Tendergate holds the key that protects the tender keys, so opening is possible. Any use of it is a deliberate, logged act.
For a private purchase, a buyer may run an open tender instead: the buyer sees each bid as it arrives, and the tender page says so before you bid.
A qualifying outage extends the deadline by one working day: at least 120 minutes in the last 24 hours or 10 minutes in the last four hours. Opening waits for the extension to reach the sealing service.
Formats: PDF, EDOC, ASiC-E, SCE, BDOC, DOCX, DOC, XLSX, XLS, ODT, ODS, ZIP, JPG, PNG, DWG, DXF. Limits: 250 MB per file (50 MB on phones), 1 GB and 50 files per bid. Original signed bytes are preserved.
Every receipt is signed by Tendergate. You can check it on the receipt verification page.
Who can access the keys
Tendergate operates the sealing service and holds its keys. Until the regulated deployment moves the keys into a hardware module in Latvia, an operator with direct access to those keys could decrypt outside the application. Every in-application decryption requires the appointed opener approvals and is signed. A company's first submission key is confirmed with a code sent to the account email, so a compromised Tendergate application could add the first key for a company that has none. Once a company has a key, every new key needs approval from an existing one.