How Req2QA protects your documents and access. Last updated: 2026-09-09
All traffic to and from Req2QA is encrypted via HTTPS. The service also sends standard hardening headers (HSTS, X-Frame-Options, X-Content-Type-Options, a restrictive Content-Security-Policy) to reduce common web attack surfaces.
Every analysis requires a private access code issued to your organization. Repeated failed attempts from the same source are automatically rate-limited, and the service is configured to deny all access if it is ever misconfigured, rather than silently allowing it through.
Uploaded documents are used only to generate your report and are not stored afterward. Only the resulting report and workbook are retained, for a limited time, and are reachable only via a private, cryptographically signed link that expires automatically — not by a guessable or permanent URL.
Analysis is performed using Anthropic's Claude API. Your document content is sent to Anthropic solely to generate your report and is not used to train any model. No other third party receives your document content.
The service enforces file-size limits, validates that uploaded files match their claimed type before processing them, and sanitizes generated spreadsheet output against formula-injection. Error messages shown to users never expose internal system or vendor details; full diagnostic information is logged securely on our side only.
To diagnose an issue you report, we keep an internal step-by-step log of each run for up to 90 days, accessible only through a separate, password-protected internal tool — not reachable through the application itself, and never through your own access code. These logs never contain login credentials or any value typed into a form field. Live-execution screenshots are retained for the usual 7-day report window; the 90-day log instead keeps only a cryptographic fingerprint of each screenshot, sufficient to verify a screenshot's authenticity without our retaining the image itself. See our Privacy Policy for the full retention breakdown.
If your security team needs more detail for a vendor review — a completed questionnaire, a data processing summary, or anything else — contact kalyan@req2qa.com.