Trust
Security Summary
This summary states current safeguards and material limitations supported by implementation and operational evidence; it is not a certification.

Data protection

Public traffic uses HTTPS/TLS. Managed database, EU-jurisdiction object storage, and backup services provide encryption at rest where configured. Secrets are supplied through deployment configuration and excluded from source control.

Identity and authorization

Backend-managed authentication, MFA, sessions, scoped role checks, and resource authorization protect organizations, projects, forms, records, media, billing, and privileged actions.

Operations and resilience

Source control, reviewed migrations, leased background jobs, monitoring, error reporting, backups, deletion workers, and incident procedures support availability, recovery, and accountability.

Customer data and sensitive uses

Customers control form purposes and content and must establish lawful bases, Article 9 conditions where needed, notices, retention, security, and DPIA screening. Reform processes customer form data on documented instructions.

Customer-authored scripts

Customers are responsible for ensuring that calculations and event scripts they create or deploy are lawful, do not harm respondents or third parties, and comply with the Product Terms and the Acceptable Use and Restricted Data Policy. Reform may restrict or suspend scripts or use that violates those requirements.

Vendors, incidents, and contact

Current subprocessors, roles, regions, and transfer information are listed on the Subprocessors page. Suspected incidents are recorded, contained, assessed, and escalated using private operational contacts. Public questions may be sent to support@paqu.io or privacy@paqu.io.