GovConTrack is built for federal contractors who handle sensitive opportunity and contract data. Here's how we protect it.
GovConTrack is hosted on Base44's managed cloud infrastructure, backed by Supabase for database and file storage. All infrastructure runs in US-based data centers with high availability and redundancy.
All data is encrypted in transit using TLS 1.2+ (HTTPS enforced). Data at rest is encrypted using AES-256 at the storage layer via Supabase's managed encryption.
Database backups are performed automatically on a daily cadence with point-in-time recovery available. Backups are stored in geographically separate locations.
Access to production systems is restricted to authorized personnel only. Role-based access control (RBAC) is enforced at the application layer. All admin actions are logged in an immutable audit trail.
In the event of a confirmed security incident, affected users will be notified within 72 hours as required by applicable data protection regulations. We maintain a documented incident response plan reviewed annually.
GovConTrack is designed with federal contractor security requirements in mind. We are actively working toward CMMC Level 1 alignment. SAM.gov data is accessed via official API endpoints only.
If you discover a security vulnerability, please disclose it responsibly by emailing security@govcontrack.org. We commit to acknowledging reports within 48 hours and keeping researchers informed of remediation progress.