Security and Data Handling
This page describes where the data you send to Re:port Flow is stored, how it is protected, and how it can be deleted. Use it for vendor security reviews and internal approvals.
It lists only facts confirmed from Re:port Flow's service configuration (application and infrastructure settings). Items we cannot back with evidence are marked Not published, and questions about operations and contracts are answered by support ([email protected]).
Summary
| Item | Details |
|---|---|
| Data hosting region | AWS Tokyo region (ap-northeast-1) |
| Encryption in transit | HTTPS. Traffic to the API (api.re-port-flow.com) goes through Cloudflare, where TLS is terminated |
| Encryption at rest | Enabled for the database and the document storage |
| Automatic deletion of generated PDFs | None (no time-based deletion is in place) |
| How to delete generated PDFs | No self-service API or screen is currently provided. Contact support |
| appkey storage | Stored encrypted (AES-256-CBC) |
| Webhook signing secret | Stored encrypted (AES-256-CBC); payloads are signed with HMAC-SHA256 |
| Public status page | Not currently provided |
| Third-party certifications | Contact support |
Where is data stored?
The application (API and PDF generation), the database, and the storage for documents and images are all in the AWS Tokyo region (ap-northeast-1). All traffic to the API passes through Cloudflare before it reaches AWS (see encryption in transit and subprocessors).
| What | AWS service | Region |
|---|---|---|
| API and PDF generation servers | Amazon ECS | Tokyo (ap-northeast-1) |
| Database (templates, output history, etc.) | Amazon RDS for MySQL | Tokyo (ap-northeast-1) |
| Generated PDFs, uploaded images, thumbnails | Amazon S3 | Tokyo (ap-northeast-1) |
| Static files of the web app (HTML / JS / CSS) | Amazon S3 + CloudFront | N. Virginia (us-east-1) |
Only the web app's static files are kept in a us-east-1 bucket so CloudFront can serve them. That bucket holds the files that make up the app's screens; it does not store generated PDFs or images you upload.
What is stored?
| Data | Where | Notes |
|---|---|---|
| Templates (designs and parameter definitions) | Database | Your edits |
| Generated PDFs | S3 | Stored under a per-workspace path (protected/.../workspace/<workspace ID>/designs/<design ID>/files/...) |
| Output history (file name, creation time, sharing settings) | Database | What the output history screen shows |
| Uploaded images | S3 | Stored under a per-workspace path |
passthrough values (strings and numbers) | Generated PDF metadata (XMP) and the database used for document search | See the warning below |
Top-level passthrough entries whose value is a string or a number are embedded in the generated PDF's search metadata (XMP) as key=value. Anyone who receives the PDF, and OS file search (Spotlight / Windows Search), may be able to see them. Do not put personal data you do not want in the PDF, such as names, into passthrough. The params merged into the document body are not part of this embedding.
How long are generated PDFs kept?
There is currently no mechanism that deletes PDFs after a set period. The only lifecycle rule on the document storage discards incomplete uploads after 7 days; no rule deletes generated PDFs.
The maximum retention period is Not published. For documents you must keep long term, we recommend downloading a copy as well.
How do I delete generated PDFs?
There is currently no API or screen that lets users delete PDFs from the output history themselves. To have them deleted, contact support ([email protected]). Support also answers questions about how deletion is carried out, its granularity, and its scope (including how records about your subscription billing and contract are handled).
Stop sharing a public link
If a PDF is shared through a public link (public), changing its sharing setting back to workspace only (workspace) in the web app stops that link from opening it. Public links have no expiry. See "Share URLs" in Template Capabilities.
How is data encrypted in transit?
- The API and the web app are served over HTTPS.
- All traffic to the API (
api.re-port-flow.com) goes through Cloudflare. The client's TLS connection is terminated at Cloudflare, which forwards the request to the API servers on AWS. Request contents (including merge data such asparams) and the generated PDFs returned in responses therefore pass through Cloudflare, which is one of our subprocessors. - See "Security requirements" in Limitations.
How is data encrypted at rest?
| What | Encryption |
|---|---|
| Database (production) | Storage encryption enabled |
| S3 bucket for generated PDFs and images | Server-side encryption (SSE-S3 / AES-256) enabled by default; all public access blocked |
| appkey (application key) | Stored encrypted with AES-256-CBC |
| Webhook signing secret | Stored encrypted with AES-256-CBC |
| Google and Notion integration access tokens | Stored encrypted with AES-256-CBC |
| Passcodes for shared PDFs | Stored as scrypt hashes (never in plain text) |
Automated backups of the production database are kept for 7 days.
About the appkey
The appkey is stored encrypted with a reversible method (AES-256-CBC), not as a one-way hash. For how and how often to regenerate it, see API Keys.
Webhook signatures
Webhook notifications carry an HMAC-SHA256 signature made with a per-endpoint secret. See Webhooks for how to verify it.
Are there audit logs?
| Record | Contents | Visible to users |
|---|---|---|
| appkey activity | Creation, regeneration, and use (who, when, IP address, User-Agent; a hash is stored, not the key itself) | Not available |
| Approval workflow audit events | Status changes such as approve / reject, who did it, and when | Included in the approval details |
| AWS management activity (CloudTrail) | Infrastructure management operations, with tamper detection enabled | Internal operations only (not published) |
A workspace-wide activity log that users can view or export is not available.
Subprocessors
Companies that process part of the data on behalf of Re:port Flow. Only those confirmed from the service configuration are listed.
| Company | Purpose | Data involved |
|---|---|---|
| Amazon Web Services | Servers, database, file storage, message queues | All Re:port Flow data |
| Cloudflare | Proxying all traffic to the API (api.re-port-flow.com), including TLS termination; DNS; email delivery (service emails such as password resets); running the MCP server; usage measurement; relaying AI features (AI Gateway) | Complete API requests and responses (including merge data such as params and the generated PDFs), email addresses and email content, requests through MCP, usage events, inputs sent to AI features |
| Sentry | Error monitoring | Technical details when an error occurs. On the PDF generation servers, values shaped like API keys, tokens, or email addresses are masked before sending |
| Stripe | Payments and billing | Billing contact and payment details |
| Anthropic | AI features (estimating parameters from a document, design AI, etc.) | Images, PDFs, and instructions passed to the AI features |
| OpenAI | AI features (when a GPT model is selected for parameter estimation) | Same as above |
| AI features (when Gemini is selected for parameter estimation) | Same as above | |
| Hostinger (Reach) | Mailing list for product announcements | Email address and display name at sign-up |
If you do not use the AI features, no data is sent to Anthropic, OpenAI, or Google. Parameter estimation lets you choose the model, and data goes to that model's vendor. Design AI uses Anthropic models.
Integrations with Google (spreadsheets) and Notion communicate with your own account only when you enable them.
Status page and incidents
A public status page is not currently provided. For questions about an incident, contact support ([email protected]).
DPA, certifications and security reviews
For a DPA (data processing agreement), third-party certifications (such as SOC 2 or ISO 27001), or a security questionnaire, please contact support.
- Email:
[email protected] - Personal data handling: Privacy Policy
Not published
The following are not listed because we cannot back them with published evidence. Contact support if you need them.
- Uptime commitment (SLA)
- Maximum retention period for generated PDFs
- How AI vendors retain data
- Recovery objectives for incidents (RTO / RPO)
Changelog
| Date | Change |
|---|---|
| 2026-10-01 | First version |