Procurement brief · July 27, 2026

RichTextEditor procurement one-pager

A scoping document for technical, legal and vendor reviews. The signed quote and license agreement control if this summary differs from a transaction document.

Product
RichTextEditor 2.4.0 public stable; self-hosted rich-text editing component.
Commercial model
Perpetual license for the purchased version; one year of updates included; no required per-seat or AI-credit meter.
Deployment
JavaScript runtime plus framework integrations deployed in customer-controlled applications and infrastructure.
Customer content
No required RichScripts content-processing service. Storage, collaboration and AI routes are selected and operated by the customer.
AI
Optional, provider-agnostic BYOK integration. The customer controls provider account, region, retention, logging and authorization.
Collaboration
Optional self-hosted Yjs endpoint with signed room tokens, origin/connection limits, persistence and Redis multi-instance fan-out.
Accessibility
WCAG 2.2 AA is the target. A criterion-level self-assessment is published; independent audit and formal VPAT/ACR remain open requirements.
Security assurance
Security architecture and shared responsibilities are published. No SOC 2, ISO 27001 or penetration-test attestation is claimed.
Support and updates
Support level and redistribution rights vary by license tier; confirm the exact quote and license agreement before purchase.

Items to resolve before approval

  • Confirm license scope, legal entity, domains, developers, SaaS/OEM use and support tier.
  • Validate the editor using representative content, browsers, assistive technology and deployment controls.
  • If certification, a formal VPAT/ACR, pen-test report, DPA or fixed security-response SLA is mandatory, treat it as unresolved until supplied in writing.
  • Document which party operates uploads, collaboration, persistence, AI providers, keys, logs, backups and incident response.