Reqnora

Security Policy

Last updated: August 29, 2026

Our safeguards

We use hashed passwords, hashed API keys, session cookies, optional TOTP 2FA for approvals, HTTPS for production traffic, and plan/rate limits to reduce abuse.

Your responsibilities

Protect passwords, API keys, webhook secrets, and physical/device access.

Enable authenticator 2FA for approvals.

Revoke keys immediately if exposed.

If credentials leak because of user action or negligence, Reqnora is not responsible for resulting account takeover or data exposure.

Incident guidance

If you suspect compromise: change password, revoke API keys, rotate webhook secrets, review history, and contact security@reqnora.com.