In plain language
- Every store runs on its own, so one store's problem never affects another.
- Every change is checked before it goes live, and you can undo any change in one click.
- Passwords and keys are never stored in plain text and never sent to the AI.
- Reqursor Platform runs in the EU, in data centers in Germany and Finland.
- Found a vulnerability? Email [email protected].
1. About this page
This page explains how Reqursor Platform keeps your clients' stores and your data safe. Reqursor Platform is in early access, so we update this page as the product grows.
2. Where it runs
Reqursor Platform runs in the EU, in data centers in Germany (Falkenstein and Nuremberg) and Finland (Helsinki). See GDPR and Data Hosting for what data we process and where.
3. Every store runs on its own
Each store runs in its own isolated environment, with its own private network and storage. No store can reach another store's data, and no organization can see another organization's stores, settings or status. This is built into how Reqursor Platform works, not a setting someone has to remember. One store's problem never affects another.
4. Every change is checked and can be undone
- You confirm every change the AI proposes before it takes effect.
- Every change is triple-checked before anything goes live. A change that fails a check is stopped with a clear report.
- If a change still causes a problem, you can undo it in one click. Orders and customers are untouched.
- Every change is recorded, so you can always see what changed.
5. Passwords, keys and the AI
- Secrets such as passwords and API keys are encrypted at rest and never stored in plain text in logs or change history.
- Account passwords are stored as a salted hash, never in plain text.
- When you use AI features, only the store settings needed for the task are sent to our AI provider. Secrets, orders, products and customer records are never included, and each request holds data for one organization only. The privacy policy lists exactly what is sent.
6. Encryption in transit
All data in transit is encrypted with TLS. Every store and custom domain gets a TLS certificate that is issued and renewed automatically.
7. Your account and your team
- Turn on multi-factor authentication when Reqursor Platform asks you to.
- Organization admins invite team members and give each one a role: Admin, Operator or Viewer.
- Keep your sign-in details safe, and contact us right away if you think someone else has access to your account.
8. Reporting a vulnerability
If you find a security problem in Reqursor Platform or its website, report it privately to [email protected]. Please don't share the details publicly.
Include:
- the page, URL or version affected;
- the steps to reproduce it;
- the impact you expect.
Never include live passwords or keys in a report. If a credential has leaked, tell us which one and change it first.
We acknowledge every report and keep you informed while we investigate and fix it. There is no bug bounty or other reward, and we don't publish security advisories or credit reporters publicly.
Security Contact
[email protected] · Reqursor Technologies, Rotterdam, The Netherlands