Security Overview
QULDEX applies layered security controls across infrastructure, application, and data layers to support confidentiality, integrity, and availability. Controls are grouped by domain and reviewed in line with product changes and operational risk assessments.
Enterprise procurement teams and certification bodies can request detailed architecture documentation, penetration test summaries, and evidence packs by contacting the security team.
Evidence Vault Encryption
All evidence files stored in the Evidence Vault are encrypted using AES-256-GCM authenticated encryption (NIST SP 800-38D). Encryption is applied server-side at ingestion; decryption is performed only at authorised retrieval. Encryption keys are never transmitted to client applications.
- AES-256-GCM: provides both confidentiality and authenticated integrity verification per file
- PBKDF2-SHA256 key derivation at 600,000 iterations — exceeds the NIST SP 800-132 recommended minimum
- Unique 12-byte IV generated per encryption operation; IVs are never reused
- Random 32-byte per-file salt with HKDF expansion for cryptographic key isolation between files
- Evidence classification labels (Public / Internal / Confidential / Restricted) enforced at the access control layer
Authentication and Session Management
Authentication is managed using short-lived JWT HS256 access tokens and refresh tokens stored in httpOnly, SameSite=Strict cookies. A Redis-backed JWT ID (JTI) denylist enables immediate token revocation with zero propagation delay.
- JWT HS256 access tokens with configurable short-lived expiry
- Redis JTI denylist: tokens are invalidated in real time on logout or account suspension
- Refresh tokens stored in httpOnly, SameSite=Strict cookies — inaccessible to browser JavaScript
- bcrypt password hashing with per-user salt at OWASP-recommended work factor
- Rate limiting on all authentication endpoints: 3–5 attempts per minute per IP address
- Login history: timestamp, IP address, device fingerprint, and success/failure status retained per user
Role-Based Access Control
Access is managed using tenant-scoped RBAC. Each organisation's data is logically isolated and inaccessible to other tenants. Module-level feature gates enforce subscription entitlements at the server layer — unlicensed modules cannot be accessed even by authenticated users.
- Tenant isolation: each organisation operates in a logically separated data boundary
- Module-level feature gates: server-enforced; bypass via client manipulation is not possible
- Least-privilege default: users receive only the permissions assigned to their defined role
- Multi-stage approval workflows require explicit authorisation before stage advancement
- Department-level data segmentation prevents cross-team data exposure within an organisation
Multi-Factor Authentication
QULDEX supports three MFA methods. MFA enforcement is configurable at account level and is required for sensitive administrative operations including plan changes and user role management.
- Email OTP: time-limited one-time code delivered to verified email address
- SMS OTP: time-limited one-time code delivered to registered mobile number
- TOTP authenticator apps: compatible with Google Authenticator, Microsoft Authenticator, and Authy
- MFA status and last-verified timestamp are visible in user profile settings
Data in Transit
All data in transit is protected using TLS 1.2 or later. Plain HTTP connections are rejected at the application layer. Internal service-to-service communication also uses encrypted channels.
Security headers are enforced on all responses: X-Frame-Options, Content-Security-Policy, X-Content-Type-Options, and Strict-Transport-Security.
Immutable Audit Trail
Every user action within QULDEX produces an append-only audit log entry. Log entries cannot be edited or deleted. The audit trail is compliant with ISO 27001 Annex A.12.4 (Logging and Monitoring) and SOC 2 CC7.2 (System Monitoring).
- Logged fields: actor ID, action type, target resource, outcome, timestamp (UTC), and IP address
- Append-only storage model: no update or delete operations are permitted on audit log entries
- Administrators can export filtered audit logs for forensic review and external audit evidence
- Configurable retention periods aligned with internal policy and regulatory requirements
Application Security
Application security controls are integrated throughout the development and deployment lifecycle. Specific controls include input validation, parameterised queries, CORS policy enforcement, and file upload validation before vault ingestion.
- Parameterised queries on all database operations (SQL injection prevention)
- File upload validation: MIME type verification, size limits, and content checks before evidence vault ingestion
- CORS policy restricts cross-origin requests to authorised origins only
- Payment webhooks verified using HMAC-SHA256 signature validation (Razorpay standard) — no card data stored
Incident Response
Security incidents are managed through a defined incident response process that includes detection, classification, containment, notification, remediation, and post-incident review. Severity classification and response SLA tracking are supported by the platform's built-in Incident Register module.
Response procedures may include containment, stakeholder communication, system remediation, and post-incident review steps aligned with ISO 27001 Annex A.16.
Responsible Disclosure
Security researchers and stakeholders who identify potential vulnerabilities are encouraged to report them through the approved contact channel. Reports should include a description of the issue, the affected component, and reproduction steps.
QULDEX acknowledges all credible vulnerability reports and provides updates on triage status. We ask that researchers allow reasonable time for remediation before public disclosure.
Security Contact
For security-related enquiries, vulnerability reports, and enterprise architecture review requests, contact the QULDEX security team using the details below.
Questions
Security enquiries and vulnerability reports: