How ReQL protects your documents and compliance data.

See where your data is processed and stored, who can access it, how the platform is reviewed, and what happens when data is deleted.

What your team can verify
Where data is stored
Choose between ReQL Cloud and supported self-hosted deployment.
Who can access it
Access is limited according to assigned roles and permissions.
How documents are used
Customer documents are processed only for the requested work and are not used to train the model.
What happens on deletion
Data follows a defined retention and deletion process.
Security review programme in progress · details published as reviews complete

Choose where ReQL runs.

Use ReQL Cloud or deploy within your own environment, depending on your organisation's infrastructure and data requirements.

Self-hosted deployment
Keep ReQL within your environment.

Deploy ReQL in your VPC or private cloud, with infrastructure, keys and logs managed according to your internal controls.

ReQL Cloud
Use a managed ReQL workspace.

Run ReQL in an isolated cloud environment with defined hosting, access, retention and deletion controls.

Deployment comparisonSelf-hosted vs ReQL Cloud
 Self-hostedReQL Cloud
InfrastructureCustomer-managedReQL-managed
Data locationCustomer environmentAgreed hosting region
Keys and logsCustomer controlsReQL controls
DeploymentSupported setupManaged setup

Your documents are not used to train ReQL's model.

Reviewed across code, application security and DPDP consent.

ReQL's review programme covers how the platform is built, how access and data flows are secured, and how consent-related product journeys are handled.

Code audit

Reviews source code, dependencies and configurations for vulnerabilities and insecure patterns.

StatusIn progress
Reviewed byTo be confirmed
DateTo be confirmed
ScopeSource, dependencies, configuration

Application security audit

Tests authentication, access controls, APIs, session handling and workspace separation.

StatusIn progress
Reviewed byTo be confirmed
DateTo be confirmed
ScopeAuthentication, access, APIs, sessions

DPDP consent audit

Reviews relevant consent notices, capture and withdrawal flows, stated purposes, retention practices and related data journeys.

StatusIn progress
Reviewed byTo be confirmed
DateTo be confirmed
ScopeConsent notices, capture, withdrawal, retention

Reviewer names, dates and outcomes are placeholders until each review is complete. We publish them only once the corresponding report is available.

What happens to a document from upload to deletion.

From encrypted upload through processing, storage, retention and deletion, every stage follows a defined process.

Uploaded
Transferred to ReQL over an encrypted connection.
Encrypted transfer
Processed
Used only for the review the user requested.
Purpose limitation
Stored
Held inside the deployment environment you chose.
Chosen deployment
Retained
Kept only as long as your workspace settings allow.
Retention settings
Deleted
Removed on the documented deletion timeline.
Documented deletion

The questions your security team will ask.

Clear answers on hosting, access, encryption, audits, retention and data export.

Yes. Documents are transferred over an encrypted connection and remain encrypted in storage within the selected deployment environment.
Access is limited to the users you invite, according to the roles and permissions assigned in your workspace. ReQL personnel access is restricted to support and operational work you request.
Each customer works within its own workspace, and documents and findings are scoped to that workspace. On self-hosted deployments, separation is provided by your own environment.
On ReQL Cloud, data is hosted in the region agreed for your workspace. On a self-hosted deployment, data stays in your own VPC or private cloud.
ReQL's review programme covers three areas. All three are currently in progress; we publish reviewer, date and outcome only once the corresponding report is available.
  • Code audit — source code, dependencies and configuration. Status: in progress.
  • Application security audit — authentication, access controls, APIs, session handling and workspace separation. Status: in progress.
  • DPDP consent audit — consent notices, capture and withdrawal flows, stated purposes and retention practices. Status: in progress.
Reports or summaries are not published yet. We do not describe ReQL as independently audited, certified or DPDP compliant until a report supports it.
Credentials and secrets are held in managed secret storage rather than in application code. On ReQL Cloud, keys are managed by ReQL. On a self-hosted deployment, keys and logs remain under your own controls.
Retention follows the settings agreed for your workspace. On request or at the end of the agreed term, data is removed through the documented deletion process, which includes removal from backups within the applicable timeline. Specific timelines are confirmed in your agreement.
You can export your documents, findings and review history from the workspace, so your records remain available to you independently of ReQL.

Have a question about ReQL?

Speak with our team about security, deployment, data handling or anything else you need to evaluate ReQL.

Book a Demo