Enterprise-Grade Security by Design

We designed Requiems API around a simple principle — data you never store cannot be leaked, breached, or subpoenaed.

Effective May 25, 2026

Core Pillar — Stateless Architecture

Every API request is processed entirely in volatile server memory (RAM). The moment your HTTP response is delivered, the payload is gone. We have no mechanism to recover it because it was never written anywhere.

  • In-memory execution — payloads never touch disk
  • Zero data retention — no database of user inputs exists
  • No cache of request/response content
  • Anonymized telemetry only — response codes and timestamps, never payload content

Transparency — The Counter API Exception

Our Counter API (/v1/technology/counter/{namespace}) is the only endpoint that persists data beyond a request. It stores a named integer count (e.g., "page-views" → 42). No request payload, no user content, no identifying data is stored — only the counter value itself. This API is rarely used and can be avoided entirely if zero-persistence is required.

Infrastructure Security

Cloudflare — Network Perimeter

  • DDoS mitigation at the edge
  • Web Application Firewall (WAF)
  • TLS 1.3 enforced on all connections
  • Rate limiting and abuse prevention

Hetzner — EU Data Centers

  • All servers located in the European Union
  • ISO/IEC 27001 certified facilities
  • Physical access controls and 24/7 monitoring
  • Redundant power and network infrastructure

API Authentication & Access Control

  • High-entropy API keys issued per account
  • Instant key revocation via dashboard
  • TLS 1.3 required on every request
  • Rate limiting enforced at the network edge

Compliance Scope

Because Requiems API maintains a 100% stateless architecture for user payloads, a traditional SOC 2 data-retention audit does not apply to our operational footprint. We satisfy the core Security and Confidentiality principles of SOC 2 by never keeping data at rest. Physical infrastructure compliance is inherited via Hetzner's ISO 27001 certification.

GDPR Alignment

No user input is stored, profiled, or transferred. EU-only infrastructure. Data minimization is structural, not procedural.

Data Processing Agreement

If your organization requires a signed DPA before integration, download our pre-filled template below or email us to execute a countersigned copy.

Want to talk? Schedule a 15-min intro call with Alexandra, our sales lead.

Alexandra Flores · Sales Lead · 15 min · No prep needed

Book a Call (opens in new tab)

Security Documents

Download our compliance documentation for your security review team.

Security & Architecture Packet

Full technical overview of our stateless architecture, infrastructure providers, and security controls. Share with your security team.

Download Security Packet

Data Processing Agreement (Template)

Pre-filled DPA template listing Requiems API as Processor with zero-retention processing terms. Fill in your organization details and countersign.

Download DPA Template

API Authentication & Security Policy

Formal policy document covering key issuance, revocation, TLS enforcement, rate limiting, and incident response procedures.

Download API Auth Policy

Need a countersigned copy or custom agreement? Email us at [email protected]

Security Contact

To report a vulnerability, request a security review, or discuss enterprise compliance requirements, contact us at [email protected]