Security & Infrastructure Disclosures
CONTRACQ Technologies • Infrastructure Architecture • contracq.in
1. Security Overview
CONTRACQ handles mission-critical tender intelligence and competitive bid surveillance for infrastructure firms, contractors, and procurement professionals. We approach platform defense with defense-in-depth security principles across data transit, storage, authentication, and physical infrastructure.
256-Bit TLS Encryption
All traffic to https://contracq.in is encrypted with modern TLS 1.3 using Let's Encrypt SSL certificates, reinforced with HTTP Strict Transport Security (HSTS max-age: 31536000) to prevent downgrade attacks.
Strict Authentication & Hashing
User passwords are never stored in plain text. We utilize cryptographic password hashing with salted algorithms. Single sign-on authentication via Google OAuth enforces strict token expiration.
PCI-DSS Level 1 Payments
Payment handling is delegated to Razorpay, certified under PCI-DSS Level 1. Credit card numbers, CVVs, and banking credentials never traverse or touch CONTRACQ servers.
Linux Hardening & SELinux
Our cloud infrastructure operates on enterprise Linux with active SELinux policy enforcement, strict firewalld boundaries, and automated daily backups of our 91,500+ tender index.
2. Vulnerability Disclosure Program
We welcome responsible security research from developers and ethical security researchers. If you discover a potential security flaw or vulnerability on CONTRACQ, please report it directly to:
Security Operations:security@contracq.in
Please include reproduction steps, HTTP logs, and relevant POCs. We acknowledge reports within 24 hours.
