Legal &
Compliance
Transparency is core to our platform. Review our terms of service, privacy policies, and security architecture below.
Terms of Service
The master agreement governing your use of the Reqursor AI platform, APIs, and managed store infrastructure.
Privacy Policy
How we collect, process, and protect your data — including how AI interactions and store declarations are handled.
Data Processing Addendum
Legal obligations for GDPR, CCPA, and data sovereignty compliance. Covers AI inference data, store content, and tenant isolation.
Enterprise-grade protection by default.
Reqursor's security model is structural, not policy-based. Isolation, encryption, and audit logging are built into the architecture — not bolted on as features.
Per-Store Isolation by Design
Every store runs in its own isolated environment — dedicated network, volumes, containers, and resource limits. No store can access another store's data, network, or processes. This is structural, not configurable.
Secrets Never in Git or Logs
Secret material (passwords, API keys, tokens) is stored in a dedicated secrets backend, referenced by opaque identifiers. Secrets never appear in Git commits, deployment artifacts, or log output.
AI Has No Access to Secrets or Business Data
The AI layer reads store declarations and health status. It never accesses secret values, customer orders, payment data, or database contents. Each LLM request contains data for exactly one tenant.
Immutable Audit Trail
Every change — AI-generated, human-authored, or migration-produced — is a Git commit with full metadata: who initiated it, whether AI-suggested, what changed, and when. Complete chain of custody from proposal to deployment.
Questions about compliance?
Our team is available to answer questions about data handling, AI data boundaries, tenant isolation, and enterprise compliance requirements.
Or email us directly at [email protected]