TI
Node.js + MCP

About Tender Intelligence

Enterprise-grade AI procurement tools — built on MCP architecture, deployed in-house, secured by design.

MCP ArchitectureHITL WorkflowAir-Gapped DeployOCDS Compliant

Security by Architecture

In May 2026, BadHost (CVE-2026-48710) was disclosed — a critical authentication bypass in Starlette/FastAPI, the foundation of most Python-based AI tools. 325 million weekly downloads. One character in the HTTP Host header bypasses path-based authorization. MCP servers were explicitly called out as high-value targets.

Tender Intelligence is built on Node.js + raw MCP — not Python, not FastAPI. This was a deliberate architectural decision. We don't inherit the dependency chain risk of shared frameworks. When a CVE like BadHost drops, we assess and patch our own stack — not someone else's timeline.

Node.js MCPPython/FastAPI

Architecture

All products share the same core architecture: a thin Next.js frontend calling Node.js MCP servers that connect to government data sources. No SaaS tenancy. No shared infrastructure.

1

Frontend Next.js / Vercel

React-based UI deployed on Vercel. Handles queries, displays results, routes to MCP servers.

2

MCP Server Node.js

Implements Model Context Protocol. Registers tools (search_austender, extract_criteria, etc.) as callable functions.

3

Data Sources Government API

AusTender OCDS API, Commonwealth Procurement Rules, state government portals (as added).

Human-in-the-Loop

AI agents cannot take unilateral external actions. All emails, compliance approvals, and procurement decisions require human approval before execution.

Environment Protection

CI/CD pauses for human approval before sends

Audit Trail

Every action logged with timestamps & approval IDs

Least Privilege

Agents can draft but never send unilaterally

In-House Deployment

We don't run a SaaS platform. Every product deploys inside client infrastructure via MCP. Your data stays on your network. Your security posture applies. Your patch cadence.

  • No shared tenancy — each deployment is isolated
  • No inherited vulnerabilities from shared framework chains
  • No ISO certification bottleneck — runs in your certified environment
  • Build + deploy fee + optional retainer. No SaaS overhead.

Products

TI

Tender Discovery

Search AusTender, analyze opportunities, draft responses — with HITL approval built in.

Try live demo
TE

Tender Evaluator

Extract criteria, check compliance, detect deviations, score bids. MCP-based with pluggable rulesets.

View prototype

Data sourced from AusTender OCDS API • Open Contracting Data Standard v1.1

All AI outputs require HITL verification