Security · 01 · Your data
Data handling.
Where customer data is hosted, how it is encrypted, and how it is retained and deleted — each statement backed by a named document.
Where it lives
Where data is hosted.
Your environmentyour cloud or your hardware
REQOPS installs in your environment and runs there. Customer records live on infrastructure you control — we can't see them, and we don't hold a copy.
Nothing phones homeno telemetry with your data in it
No records, no copies, no usage feeds sent back to us. If you want us to see something, you send it — that's the only door, and you hold it.
Backups stay yoursyour storage, your keys
Backups are written to your storage and encrypted like everything else. REQOPS configures them; you hold them.
How it's locked
Encryption and secrets.
In transitevery connection
TLS 1.2 or better on everything — browser to app, app to database, service to service. Old protocols are off, not just discouraged, and browsers are told to never try plain HTTP.
At restevery store
AES-256 on databases, file storage, and backups alike.
Keysmanaged, separated, rotated
Keys live in a managed key service — never beside the data they protect, never in code. Rotation happens on a schedule, and immediately if anything looks wrong.
Passwordsnever stored, never seen
We store modern, deliberately-slow hashes — not passwords. Nobody at REQOPS can read yours, and a database copy doesn't reveal it either.
Secretsvaulted
API keys and service credentials live in a secrets vault with access logged. The codebase is scanned so none ever hide in it.
How it leaves
Retention and deletion.
Retention runs to a written schedule, deletion follows a defined method, and offboarding ends with a written confirmation. The full schedule is published in the data retention policy.
Retentionwritten down, per data type
Every kind of data has a stated retention period and a reason. The schedule is a one-page document — it's published here.
Deletiondone properly
When time is up, deletion follows the recognised standard for actually destroying data (NIST 800-88) — including copies in backups, on their cycle.
Leavingexport first, then proof
Offboarding is: your data exported in standard formats, then deleted on the schedule, then a written deletion confirmation sent to you. You leave with everything, and we keep nothing.
Legal holdthe one exception
If law or litigation requires holding something past its date, it's frozen, logged, and released the moment the obligation ends — never quietly kept.
Whose data it is
Data subject rights and agreements.
Requestsaccess · export · fix · delete
Anyone whose data we process can ask to see it, export it, correct it, or delete it. The process is documented and runs within the statutory timeframes.
The agreementDPA, ready to sign
A data processing agreement with the standard contractual clauses for international transfers and a technical-measures annex that matches what these pages say. Legal reviewed it; you're welcome to as well.
Sub-processorspublic, dated, notified
Every vendor that touches customer data is on a public list — name, region, purpose, date. The list changes only after we tell you, and you can object before it does.
Recordswe can show our working
A record of what we process, why, under which lawful basis, kept current. It's the document regulators ask for first — ours exists before anyone asks.
Deployment overviewwhere it runs, what leaves, what never does
on requestEncryption standardone page — algorithms, keys, rotation
on requestRetention & deletion policywith the schedule attached
on requestDPA templateSCCs + technical measures annex
on requestPublic sub-processor listdated, with regions and purposes
on requestPrivacy notice & processing recordswhat, why, how long
on requestNext: Operations.