How Req2QA protects your documents and access. Last updated: 2026-09-09
All traffic to and from Req2QA is encrypted via HTTPS. The service also sends standard hardening headers (HSTS, X-Frame-Options, X-Content-Type-Options, a restrictive Content-Security-Policy) to reduce common web attack surfaces.
Application infrastructure and stored files (reports, workbooks, and the troubleshooting logs described below) are hosted on Amazon Web Services in Sydney, Australia (ap-southeast-2). Document content is additionally sent to Anthropic's Claude API for analysis, as described under AI processing below.
Every analysis requires a private access code issued to your organization. Repeated failed attempts from the same source are automatically rate-limited, and the service is configured to deny all access if it is ever misconfigured, rather than silently allowing it through.
Uploaded documents are used only to generate your report and are not stored afterward. Only the resulting report and workbook are retained, for a limited time, and are reachable only via a private, cryptographically signed link that expires automatically — not by a guessable or permanent URL.
Analysis is performed using Anthropic's Claude API. Your document content is sent to Anthropic solely to generate your report and is not used to train any model. No other third party receives your document content.
Each analysis is processed independently — your document content is not shared with, or influenced by, any other client's request. Our system prompts are designed to treat the content of your uploaded documents strictly as data to analyze, not as instructions to the AI, specifically to reduce the risk of a document attempting to alter how the system behaves. As with any AI-based system, we can't guarantee this is unbreakable against every possible attempt, and we treat it as an ongoing area of hardening rather than a solved problem. Full technical detail is available on request as part of a security review — see Questions below.
The service enforces file-size limits, validates that uploaded files match their claimed type before processing them, and sanitizes generated spreadsheet output against formula-injection. Error messages shown to users never expose internal system or vendor details; full diagnostic information is logged securely on our side only.
To diagnose an issue you report, we keep an internal step-by-step log of each run for up to 90 days, accessible only through a separate, password-protected internal tool — not reachable through the application itself, and never through your own access code. These logs never contain login credentials or any value typed into a form field. Live-execution screenshots are retained for the usual 7-day report window; the 90-day log instead keeps only a cryptographic fingerprint of each screenshot, sufficient to verify a screenshot's authenticity without our retaining the image itself. Separately, your own Audit Log (available from Client Hub) gives you a tamper-evident outcome record of your own runs — pass/fail/blocked status and a per-run integrity check — without exposing step-level detail; it covers runs from 2026-09-28 onward. Full diagnostic step-level trace remains internal-only; contact us if you need a detailed trace for a specific run. See our Privacy Policy for the full retention breakdown.
If your security team needs more detail for a vendor review — a completed questionnaire, a data processing summary, or anything else — contact kalyan@req2qa.com.