How ReQL protects your documents and compliance data.
See where your data is processed and stored, who can access it, how the platform is reviewed, and what happens when data is deleted.
Choose where ReQL runs.
Use ReQL Cloud or deploy within your own environment, depending on your organisation's infrastructure and data requirements.
Deploy ReQL in your VPC or private cloud, with infrastructure, keys and logs managed according to your internal controls.
Run ReQL in an isolated cloud environment with defined hosting, access, retention and deletion controls.
| Self-hosted | ReQL Cloud | |
|---|---|---|
| Infrastructure | Customer-managed | ReQL-managed |
| Data location | Customer environment | Agreed hosting region |
| Keys and logs | Customer controls | ReQL controls |
| Deployment | Supported setup | Managed setup |
Your documents are not used to train ReQL's model.
Reviewed across code, application security and DPDP consent.
ReQL's review programme covers how the platform is built, how access and data flows are secured, and how consent-related product journeys are handled.
Code audit
Reviews source code, dependencies and configurations for vulnerabilities and insecure patterns.
Application security audit
Tests authentication, access controls, APIs, session handling and workspace separation.
DPDP consent audit
Reviews relevant consent notices, capture and withdrawal flows, stated purposes, retention practices and related data journeys.
Reviewer names, dates and outcomes are placeholders until each review is complete. We publish them only once the corresponding report is available.
What happens to a document from upload to deletion.
From encrypted upload through processing, storage, retention and deletion, every stage follows a defined process.
The questions your security team will ask.
Clear answers on hosting, access, encryption, audits, retention and data export.
- Code audit — source code, dependencies and configuration. Status: in progress.
- Application security audit — authentication, access controls, APIs, session handling and workspace separation. Status: in progress.
- DPDP consent audit — consent notices, capture and withdrawal flows, stated purposes and retention practices. Status: in progress.
Have a question about ReQL?
Speak with our team about security, deployment, data handling or anything else you need to evaluate ReQL.