Skip to main content

Security and Data Handling

This page describes where the data you send to Re:port Flow is stored, how it is protected, and how it can be deleted. Use it for vendor security reviews and internal approvals.

How this page is written

It lists only facts confirmed from Re:port Flow's service configuration (application and infrastructure settings). Items we cannot back with evidence are marked Not published, and questions about operations and contracts are answered by support ([email protected]).


Summary​

ItemDetails
Data hosting regionAWS Tokyo region (ap-northeast-1)
Encryption in transitHTTPS. Traffic to the API (api.re-port-flow.com) goes through Cloudflare, where TLS is terminated
Encryption at restEnabled for the database and the document storage
Automatic deletion of generated PDFsNone (no time-based deletion is in place)
How to delete generated PDFsNo self-service API or screen is currently provided. Contact support
appkey storageStored encrypted (AES-256-CBC)
Webhook signing secretStored encrypted (AES-256-CBC); payloads are signed with HMAC-SHA256
Public status pageNot currently provided
Third-party certificationsContact support

Where is data stored?​

The application (API and PDF generation), the database, and the storage for documents and images are all in the AWS Tokyo region (ap-northeast-1). All traffic to the API passes through Cloudflare before it reaches AWS (see encryption in transit and subprocessors).

WhatAWS serviceRegion
API and PDF generation serversAmazon ECSTokyo (ap-northeast-1)
Database (templates, output history, etc.)Amazon RDS for MySQLTokyo (ap-northeast-1)
Generated PDFs, uploaded images, thumbnailsAmazon S3Tokyo (ap-northeast-1)
Static files of the web app (HTML / JS / CSS)Amazon S3 + CloudFrontN. Virginia (us-east-1)

Only the web app's static files are kept in a us-east-1 bucket so CloudFront can serve them. That bucket holds the files that make up the app's screens; it does not store generated PDFs or images you upload.


What is stored?​

DataWhereNotes
Templates (designs and parameter definitions)DatabaseYour edits
Generated PDFsS3Stored under a per-workspace path (protected/.../workspace/<workspace ID>/designs/<design ID>/files/...)
Output history (file name, creation time, sharing settings)DatabaseWhat the output history screen shows
Uploaded imagesS3Stored under a per-workspace path
passthrough values (strings and numbers)Generated PDF metadata (XMP) and the database used for document searchSee the warning below
passthrough values stay inside the PDF

Top-level passthrough entries whose value is a string or a number are embedded in the generated PDF's search metadata (XMP) as key=value. Anyone who receives the PDF, and OS file search (Spotlight / Windows Search), may be able to see them. Do not put personal data you do not want in the PDF, such as names, into passthrough. The params merged into the document body are not part of this embedding.


How long are generated PDFs kept?​

There is currently no mechanism that deletes PDFs after a set period. The only lifecycle rule on the document storage discards incomplete uploads after 7 days; no rule deletes generated PDFs.

The maximum retention period is Not published. For documents you must keep long term, we recommend downloading a copy as well.


How do I delete generated PDFs?​

There is currently no API or screen that lets users delete PDFs from the output history themselves. To have them deleted, contact support ([email protected]). Support also answers questions about how deletion is carried out, its granularity, and its scope (including how records about your subscription billing and contract are handled).

If a PDF is shared through a public link (public), changing its sharing setting back to workspace only (workspace) in the web app stops that link from opening it. Public links have no expiry. See "Share URLs" in Template Capabilities.


How is data encrypted in transit?​

  • The API and the web app are served over HTTPS.
  • All traffic to the API (api.re-port-flow.com) goes through Cloudflare. The client's TLS connection is terminated at Cloudflare, which forwards the request to the API servers on AWS. Request contents (including merge data such as params) and the generated PDFs returned in responses therefore pass through Cloudflare, which is one of our subprocessors.
  • See "Security requirements" in Limitations.

How is data encrypted at rest?​

WhatEncryption
Database (production)Storage encryption enabled
S3 bucket for generated PDFs and imagesServer-side encryption (SSE-S3 / AES-256) enabled by default; all public access blocked
appkey (application key)Stored encrypted with AES-256-CBC
Webhook signing secretStored encrypted with AES-256-CBC
Google and Notion integration access tokensStored encrypted with AES-256-CBC
Passcodes for shared PDFsStored as scrypt hashes (never in plain text)

Automated backups of the production database are kept for 7 days.

About the appkey​

The appkey is stored encrypted with a reversible method (AES-256-CBC), not as a one-way hash. For how and how often to regenerate it, see API Keys.

Webhook signatures​

Webhook notifications carry an HMAC-SHA256 signature made with a per-endpoint secret. See Webhooks for how to verify it.


Are there audit logs?​

RecordContentsVisible to users
appkey activityCreation, regeneration, and use (who, when, IP address, User-Agent; a hash is stored, not the key itself)Not available
Approval workflow audit eventsStatus changes such as approve / reject, who did it, and whenIncluded in the approval details
AWS management activity (CloudTrail)Infrastructure management operations, with tamper detection enabledInternal operations only (not published)

A workspace-wide activity log that users can view or export is not available.


Subprocessors​

Companies that process part of the data on behalf of Re:port Flow. Only those confirmed from the service configuration are listed.

CompanyPurposeData involved
Amazon Web ServicesServers, database, file storage, message queuesAll Re:port Flow data
CloudflareProxying all traffic to the API (api.re-port-flow.com), including TLS termination; DNS; email delivery (service emails such as password resets); running the MCP server; usage measurement; relaying AI features (AI Gateway)Complete API requests and responses (including merge data such as params and the generated PDFs), email addresses and email content, requests through MCP, usage events, inputs sent to AI features
SentryError monitoringTechnical details when an error occurs. On the PDF generation servers, values shaped like API keys, tokens, or email addresses are masked before sending
StripePayments and billingBilling contact and payment details
AnthropicAI features (estimating parameters from a document, design AI, etc.)Images, PDFs, and instructions passed to the AI features
OpenAIAI features (when a GPT model is selected for parameter estimation)Same as above
GoogleAI features (when Gemini is selected for parameter estimation)Same as above
Hostinger (Reach)Mailing list for product announcementsEmail address and display name at sign-up

If you do not use the AI features, no data is sent to Anthropic, OpenAI, or Google. Parameter estimation lets you choose the model, and data goes to that model's vendor. Design AI uses Anthropic models.

Integrations with Google (spreadsheets) and Notion communicate with your own account only when you enable them.


Status page and incidents​

A public status page is not currently provided. For questions about an incident, contact support ([email protected]).


DPA, certifications and security reviews​

For a DPA (data processing agreement), third-party certifications (such as SOC 2 or ISO 27001), or a security questionnaire, please contact support.


Not published​

The following are not listed because we cannot back them with published evidence. Contact support if you need them.

  • Uptime commitment (SLA)
  • Maximum retention period for generated PDFs
  • How AI vendors retain data
  • Recovery objectives for incidents (RTO / RPO)

Changelog​

DateChange
2026-10-01First version