CONTRACQ
CONTRACQ
Security & ResilienceEnterprise Grade

Security & Infrastructure Disclosures

CONTRACQ Technologies • Infrastructure Architecture • contracq.in

1. Security Overview

CONTRACQ handles mission-critical tender intelligence and competitive bid surveillance for infrastructure firms, contractors, and procurement professionals. We approach platform defense with defense-in-depth security principles across data transit, storage, authentication, and physical infrastructure.

256-Bit TLS Encryption

All traffic to https://contracq.in is encrypted with modern TLS 1.3 using Let's Encrypt SSL certificates, reinforced with HTTP Strict Transport Security (HSTS max-age: 31536000) to prevent downgrade attacks.

Strict Authentication & Hashing

User passwords are never stored in plain text. We utilize cryptographic password hashing with salted algorithms. Single sign-on authentication via Google OAuth enforces strict token expiration.

PCI-DSS Level 1 Payments

Payment handling is delegated to Razorpay, certified under PCI-DSS Level 1. Credit card numbers, CVVs, and banking credentials never traverse or touch CONTRACQ servers.

Linux Hardening & SELinux

Our cloud infrastructure operates on enterprise Linux with active SELinux policy enforcement, strict firewalld boundaries, and automated daily backups of our 91,500+ tender index.

2. Vulnerability Disclosure Program

We welcome responsible security research from developers and ethical security researchers. If you discover a potential security flaw or vulnerability on CONTRACQ, please report it directly to:

Security Operations:security@contracq.in

Please include reproduction steps, HTTP logs, and relevant POCs. We acknowledge reports within 24 hours.