Infrastructure Protection
Security Policy
Last updated: July 30, 2026
1. Security Architecture & Commitment
At Quarkova (https://quarkova.com), founded by Sunil Baran Mishra (Udyam Registration: UDYAM-WB-12-0125801, India), security is engineered directly into our technical stack. We prioritize data minimization, encryption, isolated execution environments, and zero-retention file processing.
2. Core Technical Security Measures
All data in transit is protected using strong SSL/TLS 256-bit encryption with HTTP Strict Transport Security (HSTS) and modern cipher suites.
Image tools run in local browser memory via HTML5 Canvas. Your images are never sent over the network to any server.
PDF processing uploads are saved in isolated temporary folders and deleted immediately after download completion.
Strict CSRF token validation, input sanitization, bcrypt password hashing, and Security Headers (X-Frame-Options, X-Content-Type-Options, CSP).
3. Cloud Infrastructure & WAF Defense
Quarkova uses Cloudflare Web Application Firewall (WAF) to defend against Distributed Denial of Service (DDoS) attacks, brute-force bots, and malicious automated probing.
4. Responsible Vulnerability Disclosure Policy
We welcome independent security researchers to audit our public web applications responsibly. If you discover a security vulnerability:
- Submit a detailed vulnerability report to contact@quarkova.com.
- Please allow our engineering team 48 hours to acknowledge and investigate the issue before any public disclosure.
- Do NOT access, alter, or destroy user data during testing.
5. Contact Security Team
Founder: Sunil Baran Mishra (Udyam: UDYAM-WB-12-0125801)
Security Contact: contact@quarkova.com
uarkova