Security and data handling

Privacy by architecture, not by policy.

ReqFit was built by people who have written proposals and completed due diligence questionnaires containing pricing strategy, methodology, security posture, and competitive positioning. We treat your documents the way we would want ours treated.

Cyber Essentials Issued by IASME, valid to 27/05/2027
ICO ZC111039 CASM Labs Ltd, UK registered
UK GDPR DPA published and live
TLS 1.3 + ML-KEM Post-quantum key agreement
No model training Your documents train nothing

The data lifecycle, end to end

What arrives, what happens to it, and what is left afterwards.

InputRFP or DDQ
InputProposal or response
TLS 1.3Post-quantum
Secure zone Processed in memory Stateless, loglessAES-256 at rest
TLS 1.3Post-quantum
DiscardedSource documentsPurged from runtime memory
RetainedRequirements listHeld against your account
90 daysReportIn your dashboard, delete any time

Source documents are discarded once your report is generated. The extracted requirements list is retained against your account so re-runs measure against the same fixed set of requirements. Reports stay in your dashboard for 90 days, with manual delete available throughout.

ReqFit holds no document store and writes no request body logs. Your proposal and the buyer's requirements document are processed in memory on Google Cloud Vertex AI, used to generate your report, then purged from runtime memory.

What we keep, what we discard

Eight specifics, each one checkable.

Stateless

Stateless analysis

Your proposal and the buyer's requirements document are processed in memory and purged from runtime memory immediately upon report delivery. ReqFit holds no long-term document store.

Logless

Logless by design

We do not keep audit logs of document content. The system processes your files and forgets the content. Operational logs are kept for service reliability but contain no customer document text.

Retention

Requirements retained for accuracy

When you upload a buyer's requirements document, we extract the requirements list and keep it against your account. This means that if you re-run a review on an improved proposal, we measure it against the same fixed set of requirements. The source document is deleted; only the structured requirements list is retained, and it is cleared on account deletion.

Training

No training on your data

Customer documents are processed via Google Cloud Vertex AI under Google's Service Specific Terms, which restrict use of your prompts and outputs for AI model training. Prompts are not logged or retained by the platform after your report is generated. Your content does not improve any AI model, ours or anyone else's.

Encryption

Encrypted in transit and at rest

Documents are encrypted in transit using TLS 1.3 and at rest using AES-256 within Google Cloud infrastructure for the brief moments data is held during processing. Account authentication uses passkey-grade credential handling. Connections additionally support hybrid post-quantum key agreement, detailed below.

Jurisdiction

UK based and ICO registered

ReqFit is operated by CASM Labs Ltd, registered in England and Wales (company number 17115248) and registered with the UK Information Commissioner's Office (ICO registration ZC111039). We process data in accordance with UK GDPR and the Data Protection Act 2018. Read our UK GDPR data protection statement.

Architecture

No external AI accounts required

Unlike tools that ask you to connect your OpenAI or Anthropic API key, ReqFit handles all AI infrastructure. You do not authorise external accounts, expose your own AI credentials, or share your data with multiple providers.

Payments

Payments isolated via Paddle

Paddle is our Merchant of Record. ReqFit does not capture, view, or store payment card details. Paddle is PCI-DSS compliant and is used by thousands of SaaS companies worldwide. The same privacy-first principle that protects your proposal data protects your payment information.

Secure today, and tomorrow

Post-quantum encryption

Connections to ReqFit support TLS 1.3 with hybrid post-quantum key agreement (X25519MLKEM768, built on ML-KEM, the algorithm standardised by NIST in FIPS 203), negotiated automatically by modern browsers through Google Cloud's global load balancing infrastructure. The same front end shields the platform against denial of service attacks through Google Cloud Armour.

This defends against harvest now, decrypt later attacks, where an attacker records encrypted traffic today in the hope of decrypting it once quantum computers mature. The UK's National Cyber Security Centre considers the threat serious enough to have set a national roadmap for migrating every organisation to post-quantum cryptography by 2035. We have not waited. If a post-quantum connection is not negotiated, it will not be our end that declined it.

Key exchange
X25519MLKEM768

You can verify this yourself: open ReqFit in Chrome, then check DevTools > Security. The key exchange shows as X25519MLKEM768.

Migration timeline
Enabled nowReqFit, in production 2035NCSC migration deadline

Compliance at a glance

The four answers a vendor onboarding form usually asks for.

Sub-processors
Google Cloud Vertex AI handles document processing. Our full sub-processor list, including the supporting providers for customer support and email, is published in Schedule 3 of our Data Processing Agreement.
Encryption
TLS 1.3 in transit with hybrid post-quantum key agreement (ML-KEM, NIST FIPS 203). AES-256 at rest within Google Cloud infrastructure for the brief moments data is held during processing.
Retention
Source documents purged from runtime memory immediately after report generation. Requirements lists retained against the account for re-run accuracy, cleared on account deletion. Reports stored for 90 days in the user's dashboard, with manual delete available throughout.
Regulatory
UK GDPR aligned. ICO registration ZC111039. Our standard Data Processing Agreement is live, with a bilateral signed copy available for enterprise procurement on request to security@reqfit.com. See also our UK GDPR statement, Terms and Conditions, and Privacy Policy.
For procurement and security review questions, contact security@reqfit.com

We're Cyber Essentials certified

Verified certificate
Cyber Essentials IASME, 27/05/2026. Valid to 27/05/2027.

We hold Cyber Essentials certification, issued by IASME on 27/05/2026 and covering the whole organisation. The scheme verifies the five technical control areas defined by the UK National Cyber Security Centre: secure configuration, access control, security update management, malware protection, and firewalls. Our certificate is valid through 27/05/2027 and can be verified by clicking on the smart badge icon.

We do not yet hold SOC 2 Type 2 or ISO 27001. Both are on the roadmap, but they take time to obtain honestly and we would rather build the certification properly than market it before it is real.

Architecture
We do not retain your source documents.
Platform
Google Cloud holds SOC 2, ISO 27001, and ISO 27018.
Registration
Registered with the UK ICO under reference ZC111039.

If your procurement process requires SOC 2 today, we are probably the wrong tool. If it does not, you will find that stateless and logless answers most of the questions SOC 2 is designed to answer in the first place.

Security FAQs

Grouped by what procurement usually asks first.

Documents and retention

Documents are processed in memory on Google Cloud Platform using Vertex AI. Static customer administration data (account profile, credit balance, retained requirements lists, report records) resides within European cloud infrastructure. Transient text extraction for AI inference may be routed securely across dynamic international regions selected for capacity and performance, governed by our Data Processing Agreement and the UK Extension to the EU-US Data Privacy Framework. Enterprise customers with specific data residency requirements can discuss these with us on request.

Your proposal documents and the buyer's requirements document are purged from runtime memory immediately after the report is delivered. The structured requirements list extracted from the buyer's document is retained against your account so that re-running a review on an improved proposal is measured against the same fixed set of requirements. You can delete your account at any time, which removes all retained data including stored requirements lists.

Reports are kept in your account, viewable online with PDF and DOCX download available throughout, for ninety (90) days from generation. You can delete a review manually at any point within that window. After 90 days, reports are deleted automatically. We encourage you to download your reports while they are available; downloaded copies remain on your own device after our retention window ends.

No. Your documents are processed via Google Cloud Vertex AI under Google's Service Specific Terms, which restrict use of your prompts and outputs for AI model training. They are used only to produce your review report, are not logged or retained by the platform after the report is generated, and are not used to improve any AI model, ours or anyone else's.

Account deletion removes all retained data associated with your account, including stored requirements lists from previous reviews, account configurations, and any reports still within their 90-day retention window. Reports you have already downloaded remain on your own device. Account deletion is permanent.

Compliance and certification

Yes. ReqFit is operated by CASM Labs Ltd, registered with the UK Information Commissioner's Office under registration ZC111039 and bound by UK GDPR and the Data Protection Act 2018. Our standard Data Processing Agreement applies automatically when you create an account. A bilateral signed copy is available on request for enterprise procurement. Read our plain-English UK GDPR statement for the full picture.

Our standard Data Processing Agreement is published and applies automatically when you create an account. If you need a bilateral signed copy for your procurement or vendor onboarding process, contact us at security@reqfit.com and we will send you a Word version for execution. We can also countersign a DPA you provide, whichever is faster for your process.

Not yet. SOC 2 Type 2 and ISO 27001 both take time to obtain properly, requiring an established track record of operation rather than a point-in-time check, and we are working towards them honestly rather than marketing them aspirationally. Our underlying platform (Google Cloud) holds SOC 2, ISO 27001, and ISO 27018, and we hold Cyber Essentials certification, awarded on 27/05/2026 and valid to 27/05/2027, as our immediate trust signal.

Yes. Connections to ReqFit support TLS 1.3 with hybrid post-quantum key agreement (X25519MLKEM768, built on ML-KEM, NIST FIPS 203), negotiated automatically by modern browsers. This protects against harvest now, decrypt later attacks, where encrypted traffic is recorded today for decryption once quantum computers mature. You can verify it yourself in Chrome: DevTools > Security shows the key exchange for your live connection.

Access and incidents

Documents are processed automatically with no human review at ReqFit. Customer support staff have no access to document content. Reports are visible to you and to any colleagues you have invited into your organisation through admin settings (see "How do team accounts handle data access?" below for detail). Reports are not visible to users outside your organisation.

Team access is invite-only. The account owner invites colleagues into their organisation through admin settings; once a colleague accepts, team members can see each other's reviews. This supports workload sharing, peer review, and holiday cover. There is no automatic same-domain grouping, and reviews are never shared across organisations or with other ReqFit users.

If we identify a security incident affecting your data, we will notify you within 48 hours of detection, as set out in Clause 6 of our Data Processing Agreement. UK GDPR also imposes breach notification obligations, and our process is designed to meet them. The notification will include the nature of the incident, the categories of data affected, the likely consequences, and the measures we are taking. To report a suspected vulnerability or security concern, contact security@reqfit.com.

Last updated: 07/09/2026.