REQOPS
Security at REQOPS

Security overview.

The controls REQOPS operates, the standards it is assessed against, and the documentation your security team can request.

DocumentationCommon questions
SOC 2TYPE II
Report under NDA
ISO27001
Certified ISMS
GDPRCOMPLIANT
DPA + SCCs ready
PENTESTANNUAL
Retest attestation
Where it runs

Deployed in your environment.

REQOPS installs in your environment — your cloud account or your own hardware. Customer records remain on infrastructure you control, and no customer data is transmitted to REQOPS.

At a glance

Summary of the program.

Encryption

Encryption in transit and at rest.

TLS 1.2+ on every connection, AES-256 on every store and backup. Keys are held in a managed key service and rotated on schedule.

Privacy

GDPR compliance.

DPA with standard contractual clauses, a public sub-processor list, data-subject requests handled within the statutory timeframes, and confirmed deletion.

Assurance

SOC 2 Type II, ISO 27001, penetration testing.

SOC 2 Type II audited and ISO 27001 certified, with independent penetration tests annually — report, certificate and attestation available under NDA.

Incidents

A documented incident response plan.

Severity matrix, named owners, prepared notification templates — customers notified without undue delay, regulators within 72 hours where GDPR applies.

AI

Customer data is not used to train models.

A transparency statement lists every AI feature and the data that reaches it. No-training commitments are contractual, with human oversight and an AI kill switch.

Access

Least-privilege access, reviewed quarterly.

Role-based access, an append-only audit trail, same-day removal for leavers, and signed quarterly access reviews.

Common questions

Frequently asked in security reviews.

SECURITY REVIEW
QUESTION 1 OF 5
› Where is our data hosted?
On your servers. REQOPS runs in your environment — your cloud account or your own hardware — and customer records never leave infrastructure you control.
artifact: deployment overview
EVERY ANSWER NAMES ITS ARTIFACT
A sample of the standard review questions
Documentation

Available documentation.

The documents security reviews request, maintained and dated. Several are published in the policy library; the remainder are available on request.

01
Security overviewsummary of the security program
02
Information security policy setthe internal policy set
03
Architecture & data-flow diagramswith trust boundaries marked
04
Data classification schemesensitivity classes and handling rules
06
Incident response planincluding notification templates
07
Kill-switch runbookemergency access and feature shut-off
08
Encryption standardalgorithms, key management, rotation
09
DPA templatewith SCCs and the TOMs annex
12
Data-subject request processaccess, export, correction, deletion
13
Risk register & methodidentified risks and treatments
14
Vendor due-diligence filesper-vendor assessments
15
AI transparency statementAI usage and data flows
Operating cadence

Recurring security activities.

These activities run on a schedule, and each produces dated evidence.

Weekly

Dependency alert review

Every alert closed or fixed, with the record retained.

Monthly

Scans and backup checks

Vulnerability scan reviewed; backup jobs verified as running.

Quarterly

Access reviews

Every account on every system reviewed for need and least privilege, with sign-off.

Annually

Restore test

A backup restored and verified.

Annually

Incident exercise

A tabletop run of the incident response plan, with notes and actions filed.

Annually

Penetration test

Independent testers, full report, fixes retested — attestation letter available.

Request documentation.

Send a questionnaire or name the documents you need at hello@reqops.io. NDA-controlled documents are provided under a signed NDA.