Security

Security at Contrax

Your bids, business data, and proposal work are business-critical. Here's exactly how we protect them — from infrastructure and encryption to access controls, data handling, and incident response.

Infrastructure

Built on trusted, enterprise-grade providers

Contrax runs on leading cloud infrastructure. We deliberately keep our stack small and well-audited — every provider below is a major platform with SOC 2-type controls, published security documentation, and industry-standard compliance programs.

Hosting — Vercel

The Contrax application is served from Vercel's global edge network. Vercel operates SOC 2 Type II–certified infrastructure, provides DDoS protection and WAF capabilities, and manages TLS certificates automatically.

Database — Neon PostgreSQL

Application data lives in Neon's serverless Postgres. Data is stored in Neon's cloud, encrypted at rest, backed up, and protected by their access controls and security program.

AI — OpenAI

AI features (summaries, scoring, proposal drafting) use OpenAI's API. We send only the information needed for the requested feature and rely on OpenAI's security, privacy, and data-use commitments for API traffic.

Encryption

Protected in transit and at rest

In transit — HTTPS / TLS

All traffic to and from Contrax is encrypted with HTTPS using modern TLS. Every connection to our APIs, your dashboard, and our providers' services is protected against interception or tampering. We enforce secure connections end to end — the application, the database, and outbound AI and email calls all use TLS.

At rest

Data stored in our Neon PostgreSQL database is encrypted at rest using provider-managed encryption keys. Backups are encrypted as well. Your data is never stored in plaintext on disk anywhere in our stack.

Access Controls

Least-privilege access to production

Access to production systems is restricted to the few people who genuinely need it, and every access path is credential-protected and auditable.

Restricted production access

Only authorized personnel can reach production hosting, the database, and payment infrastructure. Access is granted on a least-privilege basis and reviewed as the team changes.

Credential management

Production secrets — database URLs, API keys, payment keys, and sync tokens — are stored in environment variables and provider-managed secret stores. Secrets are never committed to source control, and credentials are rotated when needed.

User authentication

Your account is protected by email/password authentication with session cookies. Within team workspaces, roles and permissions control what each member can view and do.

Application security

Server functions validate all inputs, API endpoints are authenticated where required, and deployment is automated so code reaches production through a reviewable, reproducible build.

Data Handling

Clear policies on storage, retention, and deletion

What we store

Account and business profile data (name, email, business details, preferences), bid and opportunity data you interact with, AI-generated summaries and proposals, team activity, and payment records through Stripe. We do not sell your data and do not use advertising trackers.

Retention

We retain data only as long as needed to provide the service, meet legal obligations, resolve disputes, and enforce agreements. Payment records are retained per Stripe's and applicable financial record-keeping requirements.

Deletion

You can request deletion of your account and associated data at any time via privacy@contrax.app. We respond to access and deletion requests within 30 days and remove or anonymize data we no longer need.

See our Privacy Policy for the full picture of what we collect and how we use it.

Incident Response

If something happens, you'll hear from us

No system is immune to incidents, so we plan for them. If we become aware of a security incident that affects your information, we will provide notice as required by applicable law and as appropriate to the situation — including by email to the address on your account.

  • We monitor infrastructure and application health, including automated checks and cron-based jobs.
  • We investigate suspected incidents promptly and take steps to contain and remediate them.
  • We notify affected users without undue delay when their data may have been involved, along with what we know and what we're doing about it.

Subprocessors

Third parties that process data on our behalf

Contrax uses the following subprocessors to deliver the service. Each receives only the data needed for its specific function.

SubprocessorPurposeData
VercelHosting and content deliveryApplication data served to you; server logs
NeonDatabase hostingAccount, business, bid, and proposal data
OpenAIAI processing (summaries, scoring, drafting)Content needed for the requested feature
StripePayments and billingPayment details, billing records, and transaction data
ResendTransactional emailRecipient email addresses and message content

We will update this page if we add or change subprocessors. Questions about security or data handling? Email privacy@contrax.app.

Focus on winning bids — we'll handle security

Start competing for government contracts with confidence.

Get Started