Procurement brief · July 27, 2026
RichTextEditor procurement one-pager
A scoping document for technical, legal and vendor reviews. The signed quote and license agreement control if this summary differs from a transaction document.
- Product
- RichTextEditor 2.4.0 public stable; self-hosted rich-text editing component.
- Commercial model
- Perpetual license for the purchased version; one year of updates included; no required per-seat or AI-credit meter.
- Deployment
- JavaScript runtime plus framework integrations deployed in customer-controlled applications and infrastructure.
- Customer content
- No required RichScripts content-processing service. Storage, collaboration and AI routes are selected and operated by the customer.
- AI
- Optional, provider-agnostic BYOK integration. The customer controls provider account, region, retention, logging and authorization.
- Collaboration
- Optional self-hosted Yjs endpoint with signed room tokens, origin/connection limits, persistence and Redis multi-instance fan-out.
- Accessibility
- WCAG 2.2 AA is the target. A criterion-level self-assessment is published; independent audit and formal VPAT/ACR remain open requirements.
- Security assurance
- Security architecture and shared responsibilities are published. No SOC 2, ISO 27001 or penetration-test attestation is claimed.
- Support and updates
- Support level and redistribution rights vary by license tier; confirm the exact quote and license agreement before purchase.
Items to resolve before approval
- Confirm license scope, legal entity, domains, developers, SaaS/OEM use and support tier.
- Validate the editor using representative content, browsers, assistive technology and deployment controls.
- If certification, a formal VPAT/ACR, pen-test report, DPA or fixed security-response SLA is mandatory, treat it as unresolved until supplied in writing.
- Document which party operates uploads, collaboration, persistence, AI providers, keys, logs, backups and incident response.