Req2QA Start Free Trial

Security Overview

How Req2QA protects your documents and access. Last updated: 2026-09-09

Encryption in transit

All traffic to and from Req2QA is encrypted via HTTPS. The service also sends standard hardening headers (HSTS, X-Frame-Options, X-Content-Type-Options, a restrictive Content-Security-Policy) to reduce common web attack surfaces.

Access control

Every analysis requires a private access code issued to your organization. Repeated failed attempts from the same source are automatically rate-limited, and the service is configured to deny all access if it is ever misconfigured, rather than silently allowing it through.

Document handling

Uploaded documents are used only to generate your report and are not stored afterward. Only the resulting report and workbook are retained, for a limited time, and are reachable only via a private, cryptographically signed link that expires automatically — not by a guessable or permanent URL.

AI processing

Analysis is performed using Anthropic's Claude API. Your document content is sent to Anthropic solely to generate your report and is not used to train any model. No other third party receives your document content.

Application safeguards

The service enforces file-size limits, validates that uploaded files match their claimed type before processing them, and sanitizes generated spreadsheet output against formula-injection. Error messages shown to users never expose internal system or vendor details; full diagnostic information is logged securely on our side only.

Operational troubleshooting logs

To diagnose an issue you report, we keep an internal step-by-step log of each run for up to 90 days, accessible only through a separate, password-protected internal tool — not reachable through the application itself, and never through your own access code. These logs never contain login credentials or any value typed into a form field. Live-execution screenshots are retained for the usual 7-day report window; the 90-day log instead keeps only a cryptographic fingerprint of each screenshot, sufficient to verify a screenshot's authenticity without our retaining the image itself. See our Privacy Policy for the full retention breakdown.

Questions

If your security team needs more detail for a vendor review — a completed questionnaire, a data processing summary, or anything else — contact kalyan@req2qa.com.

← Back to Req2QAPrivacy PolicyTerms of Service