Buyers
For people who look for suppliers and send inquiries or RFQs.
Can I use TUMO right after signing up? How do I verify my e-mail?
Preparing
Signing up with an e-mail address and password creates the account and signs you in immediately. Browsing published suppliers and products and drafting inquiries work right away.
Verification e-mail delivery is still being prepared. No e-mail provider is connected yet, so the verification link does not actually arrive. Until your address is verified you cannot deliver inquiries to suppliers, and you are limited to 1 organization, 3 private documents, 20 address-book contacts and 1 company access request.
Once mail delivery is connected, 'Request verification email again' on the profile screen sends a new link.
I forgot my password.
Preparing
Use 'Reset password' on the sign-in screen and enter your e-mail; the request is accepted.
Reset e-mail delivery is also still being prepared: until a mail provider is connected the reset link does not arrive, so please use the contact channel below. Accounts in a deletion grace period are not issued reset tokens.
How do I find and compare suppliers and products?
Supplier, product, insight, job, marketplace and sharing listings and search are open without signing in. The compare screen puts selected suppliers side by side.
Each item carries its public source and verification date. Current supply conditions, stock and prices must be confirmed with the company directly; TUMO is not a party to the transaction.
How do I send an inquiry or RFQ?
Go to Workspace > Inquiries > New inquiry, choose the recipient companies yourself, review the preview and approve delivery. Recommended companies are never added automatically.
Each recipient gets an independent thread: one company's replies and attachments are never visible to another.
Accounts without a verified e-mail can draft and save but cannot deliver to suppliers (verification e-mail delivery is being prepared).
What are the attachment rules, and what does 'inspection pending' mean?
PDF, UTF-8 text, PNG and JPEG files up to 7 MiB each are accepted. Archives and executables are not.
Uploads are inspected by a dedicated quarantine scanner (ClamAV). Only files whose inspection finished as clean and whose usage rights are marked can be attached or downloaded. Files still scanning, or marked as error or infected, are never shared; withdraw them and upload a safe file instead.
Each account can keep 200 documents / 500 MiB; withdrawn documents still count while something references them.
What do inquiry states and notification e-mails mean?
Your sent-inquiry screen shows only a per-recipient summary: delivered, pending or unavailable. Bounce or suppression details of the recipient's address are not shown.
'Delivered' does not mean accepted, quoted or read. Replies appear in the thread.
Notification e-mails carry minimal information; the body, attachments and prices are visible only after signing in with the right permissions. External mail delivery itself is still being prepared, so notification e-mails may not arrive yet.
Can I rely on an automated quote?
Automated quotes are computed with Decimal arithmetic strictly inside a price rule the supplier approved in advance (unit price, quantity tiers, currency, validity). AI only extracts and explains requirements; it never guesses prices, taxes, exchange rates or lead times.
Each quote shows its validity period and exclusions. Requests without a matching rule or outside its range go to the supplier for manual review, and an automated quote does not guarantee final contract terms.
Are interests and my address book a marketing consent?
No. Interests and the address book only shape browsing and inquiries; they are not consent to marketing e-mail. Marketing messages are sent only with a separate, explicit subscription.
You manage subscriptions and opt-outs on the e-mail subscriptions screen.
How do I switch between Korean and English?
Use the language switch in the header; the /ko or /en prefix in the address changes with it.
If a company has not published English material yet, the original text is shown instead. Machine-translated material is labelled separately from approved versions.
I want to delete my account. What about the grace period and cancelling?
Under Workspace > Security & MFA > Request account deletion, enter your current password (plus an app or recovery code if MFA is enabled). Every sign-in session ends immediately and sign-in is blocked during the grace period.
The grace period is an initial setting of 14 days. When it elapses the account is anonymised and personal documents, address book, subscriptions and MFA devices are purged. Counterpart companies' business records (inquiry threads, approvals, quotes) and the do-not-send list remain as anonymous references.
To cancel, confirm your e-mail and password (and MFA code if enabled) on the sign-in screen. You can sign in again afterwards; sessions and invitations that already expired are not restored.
Where are the privacy policy and terms of service?
Both are linked in the footer. They are currently drafts pending legal review; when the final versions replace them, the effective date and changes are posted.
Requests to access, correct or delete personal data can be made on the profile screen or sent to the privacy officer named in the privacy policy.
Suppliers
For organizations that manage a company profile and handle inquiries, quotes, jobs and listings.
How do I register my company and obtain management access?
Create a member organization under Workspace > Organizations, then request access to an existing company page or register a new company under Company management. A company (the legal entity) and a member organization are separate; only an organization with approved access can edit that company's public profile.
Duplicate requests for the same company do not create a new page; they attach to the existing company and are reviewed together.
Accounts without a verified e-mail can create at most 1 organization and 1 access request (verification e-mail delivery is being prepared).
What evidence does an access request need?
A company-domain e-mail or DNS confirmation combined with proof that the applicant represents or is delegated by the company. Domain ownership alone never grants access automatically.
When requesting, upload the evidence as private documents first and submit their references together with the reason for the request. Requests from shared mailboxes, agencies, subsidiaries or branches are additionally reviewed against business registration evidence, a delegation letter and the company's existing contact channel. Evidence is stored privately, separate from the public profile.
An operator makes the decision; a conflict with an existing administrator puts the request into a disputed state for separate confirmation.
Do company and product edits go live immediately?
Edits are saved as a revision first; a member with approval and publishing rights must approve and publish before the public version changes. Approval and publishing require MFA and recent authentication.
Each field carries its source, rights status and verification date. If a source is withdrawn or expires, publishing that relies on it is blocked. Editing the English text does not replace the original-language evidence.
Where do I handle received inquiries and RFQs?
In the Received box under Workspace > Inquiries. Each inquiry is an independent thread opened only for your company; replies from other companies that received the same inquiry are not visible.
Re-attaching a file in a thread requires a document your organization uploaded or the exact version actually shared in that thread. Files whose inspection has not finished cannot be attached.
What do I set up to use automated quotes?
Under Quotes & pricing, create and approve a price rule with product version, unit price, quantity tiers, currency, validity and the scope for automatic issue (MFA and recent authentication required). Only requests inside an approved rule receive a quote number automatically.
Requests without a rule, or outside its validity or range, stay in manual review. Retrying the same request against the same rule version returns the existing quote, so nothing is issued twice. Price lists and costs are visible only within your organization's permissions.
How are job postings and candidate material handled?
Register postings under Manage jobs and review applications under Applications. A candidate's résumé and profile are visible only within the purpose, recipient and profile version the candidate consented to.
If a candidate withdraws consent or deletes their account, the shared material and profile snapshot are purged; ongoing application records remain only as anonymous references. Material may not be reused for another purpose or shared onward.
How do I list marketplace items and shared resources, and handle reservations?
Marketplace listings and shared resources (equipment, space, etc.) are registered under Company management with an accurate rights status: owned, licensed or unverified. Listings are published after operator review.
Sharing requests and reservations are handled on the Sharing & reservations screen. A reservation is confirmed only within the approved capacity, and inquiries arrive as independent threads per listing.
Can I send newsletters or e-mail campaigns?
Preparing
You can create a campaign and take it through approval on the Email campaigns screen. Recipients are only those who explicitly subscribed; opt-outs and bounces are excluded automatically.
Actual external delivery is still being prepared. Until a mail provider and sender-domain authentication are confirmed, sends are recorded as pending and not executed.
How do I invite colleagues and assign roles?
Preparing
Invite members under Organizations & invitations and assign roles such as admin, approver, sales, recruiter or market_manager. An organization must always keep at least one active administrator; the last administrator cannot demote themselves or delete their account.
Invitation e-mail delivery is still being prepared. Until mail is connected the invitee receives no link, so share the invitation-acceptance page address directly.
Do I have to enable MFA?
Organization roles admin, approver, sales, recruiter and market_manager, and operators, need an MFA check for private work. Sensitive actions such as approving and delivering inquiries, approving and issuing price rules, approving content or campaigns and approving sources additionally require recent authentication (re-confirmed within 5 minutes).
On Security & MFA, register the key in an authenticator app and receive 10 recovery codes. Recovery codes are shown only once at issue, so store them safely; if lost, reissue them with an app code.
Operators
For operators who review company access, source policies, fact candidates and crawl jobs.
Where are the operator screens and what do they require?
Company access review, source registration and review (including the fact-candidate and crawl-job sub-screens) and content or campaign approval all live inside Workspace and appear only for accounts with operator (staff) rights.
Operator reads require an MFA check; writes such as approve, activate, withdraw and creating or cancelling crawl jobs require MFA plus recent authentication. There is no separate admin sign-in path.
On what basis are access requests approved?
Check the company-domain e-mail or DNS confirmation together with evidence that the applicant represents or is delegated by the company. Domain ownership alone is not enough; shared mailboxes, agencies and subsidiaries additionally need business registration evidence and the company's existing contact channel.
Duplicate requests for one company are reviewed as one; a conflict with an existing active administrator is held as disputed with the resolution reason, evidence and the person who changed rights recorded. Decisions are stored with reason and scope, and editing or private-evidence access is blocked before approval, after rejection and after revocation.
What is a source policy and how is it activated?
A source policy is the central record of allowed hosts and fields, rights evidence, per-purpose permissions (collect, store, publish, translate, AI), the robots check record and an expiry date. An organization or operator registers it as a draft and an operator reviewer activates it.
Active policies are never edited, only withdrawn; changed conditions go into a new policy for a fresh review. Activation and withdrawal require MFA, recent authentication, the current version and a reason. Activating a policy does not replace the source's actual permission to use its material.
In what order do I review fact candidates (assertions)?
Review the per-field candidates extracted from a source document by rules (with optional AI span selection). A candidate without an original-text excerpt is stored as unsupported and cannot be verified.
Two or more live values for one single-valued field across documents are flagged as a conflict. Differing values, units or scopes are never merged; a change proposal is approvable only after one verified candidate is selected.
Approving a change proposal does not alter the public field directly: it creates a draft revision owned by the managing organization, which still goes through the existing approve-and-publish flow. Verify, reject, select and approve actions are all audited.
When can crawl jobs be run?
Preparing
Crawl jobs can be created only within the hosts, fields and purposes of an active source policy, and apply per-host robots checks, daily budgets, minimum intervals, 429/5xx/403 handling and resume cursors. Collected pages are registered only as draft documents with contacts and identifiers masked; nothing is published automatically.
Because permission to use the real sources (DATA-001) is not yet confirmed, production crawling has not started. The crawl-job screen is implemented, but runs against real sites and browser verification are still being prepared; only synthetic-page checks have passed.
What is cleaned up when a source is withdrawn?
Withdrawing a document or policy rejects its live candidates, clears selections that pointed at them and supersedes pending change proposals in the same transaction. Expired sources are cleaned up the same way by a periodic job.
AI answer caches are removed by the cleanup worker. Chunk, embedding and translation re-validation is not implemented yet because those derivatives do not exist. Already approved revisions are blocked from publishing by the source gate.
What if a collected document or uploaded PDF contains instructions?
Instructions inside collected documents, web pages, PDFs or inquiry bodies carry no execution authority. AI extraction only selects original-text spans, values are produced by server rules, and no external document can trigger approval, publishing or sending.
Reject material containing suspicious instructions and record the reason. Attachment contents are never executed, independent of the quarantine scanner result.
Why do inquiry notifications and verification e-mails stay pending?
Preparing
No mail provider is connected yet, so every mail event is recorded as captured or blocked and nothing leaves the system. That is a processing record, not proof of delivery.
Real sending starts only after the provider and sender domain (SPF/DKIM) are confirmed and sending is switched on. Until then, describe verification, reset, invitation and inquiry notification e-mails as being prepared. The sender's screen never exposes bounce or suppression details of recipient addresses.
What must an operator do about a user's account deletion request?
Request, grace period and purge are handled by the user's own request and a periodic job; operators do not delete on the user's behalf. During the grace period (initial value 14 days) sign-in is blocked and the user can cancel from the sign-in screen.
After purge, counterpart organizations' inquiry, approval and quote records and the do-not-send list remain as anonymous references. Files whose deletion was refused during purge stay withdrawn and are reclaimed by the sweeper. If a user who cannot sign in asks for cancellation, verify their identity and follow the account-deletion runbook.
Contact
- [to be provided]
- Hours
- [to be provided]
Items marked [to be provided] must be filled in by the operator with verified values. Send personal-data requests to the privacy officer named in the privacy policy.
Help version: 2026-09-11