Security Policy
Last updated: August 29, 2026
Our safeguards
We use hashed passwords, hashed API keys, session cookies, optional TOTP 2FA for approvals, HTTPS for production traffic, and plan/rate limits to reduce abuse.
Your responsibilities
Protect passwords, API keys, webhook secrets, and physical/device access.
Enable authenticator 2FA for approvals.
Revoke keys immediately if exposed.
If credentials leak because of user action or negligence, Reqnora is not responsible for resulting account takeover or data exposure.
Incident guidance
If you suspect compromise: change password, revoke API keys, rotate webhook secrets, review history, and contact security@reqnora.com.