Enterprise-Grade Security by Design
We designed Requiems API around a simple principle — data you never store cannot be leaked, breached, or subpoenaed.
Effective May 25, 2026
Core Pillar — Stateless Architecture
Every API request is processed entirely in volatile server memory (RAM). The moment your HTTP response is delivered, the payload is gone. We have no mechanism to recover it because it was never written anywhere.
- In-memory execution — payloads never touch disk
- Zero data retention — no database of user inputs exists
- No cache of request/response content
- Anonymized telemetry only — response codes and timestamps, never payload content
Transparency — The Counter API Exception
Our Counter API (/v1/technology/counter/{namespace}) is the only endpoint that persists data beyond a request. It stores a named integer count (e.g., "page-views" → 42). No request payload, no user content, no identifying data is stored — only the counter value itself. This API is rarely used and can be avoided entirely if zero-persistence is required.
Infrastructure Security
Cloudflare — Network Perimeter
- DDoS mitigation at the edge
- Web Application Firewall (WAF)
- TLS 1.3 enforced on all connections
- Rate limiting and abuse prevention
Hetzner — EU Data Centers
- All servers located in the European Union
- ISO/IEC 27001 certified facilities
- Physical access controls and 24/7 monitoring
- Redundant power and network infrastructure
API Authentication & Access Control
- High-entropy API keys issued per account
- Instant key revocation via dashboard
- TLS 1.3 required on every request
- Rate limiting enforced at the network edge
Compliance Scope
Because Requiems API maintains a 100% stateless architecture for user payloads, a traditional SOC 2 data-retention audit does not apply to our operational footprint. We satisfy the core Security and Confidentiality principles of SOC 2 by never keeping data at rest. Physical infrastructure compliance is inherited via Hetzner's ISO 27001 certification.
GDPR Alignment
No user input is stored, profiled, or transferred. EU-only infrastructure. Data minimization is structural, not procedural.
Data Processing Agreement
If your organization requires a signed DPA before integration, download our pre-filled template below or email us to execute a countersigned copy.
Want to talk? Schedule a 15-min intro call with Alexandra, our sales lead.
Alexandra Flores · Sales Lead · 15 min · No prep needed
Security Documents
Download our compliance documentation for your security review team.
Security & Architecture Packet
Full technical overview of our stateless architecture, infrastructure providers, and security controls. Share with your security team.
Data Processing Agreement (Template)
Pre-filled DPA template listing Requiems API as Processor with zero-retention processing terms. Fill in your organization details and countersign.
API Authentication & Security Policy
Formal policy document covering key issuance, revocation, TLS enforcement, rate limiting, and incident response procedures.
Need a countersigned copy or custom agreement? Email us at [email protected]
Security Contact
To report a vulnerability, request a security review, or discuss enterprise compliance requirements, contact us at [email protected]