Normal desktop project processing is designed to remain on the customer device. The reviewed package contains no automatic project-content upload endpoint.
Controls you can inspect. Boundaries you can understand.
REQVERA is designed around local project control, explicit release gates and evidence-linked decisions. This page states what the reviewed product architecture supports — and what it deliberately does not claim.
The reviewed source contains AES-256-GCM authenticated-encryption routines for project data and Argon2id + AES-256-GCM protection for portable backups.
Named blockers can keep release closed. Buyer-portal review and final submission remain human decisions.
No product telemetry integration is configured in the reviewed package. This statement does not cover unrelated operating-system, browser, antivirus or store-client traffic.
Release integrity.
Buyer-facing output is tied to an inspected release state rather than treated as an ungoverned export.
REQVERA’s controlled release architecture links buyer-facing output to a versioned control state and integrity evidence. Once readable exports are explicitly generated, their storage, transfer and retention sit under the customer’s own controls.
Vulnerability disclosure.
If you believe you have found a security vulnerability in the public website or REQVERA software, report it to [email protected] with the subject “REQVERA security report”. Include the affected URL or product version, reproducible steps and impact. Do not include tender files, buyer-confidential material, credentials or live customer data. The machine-readable reporting route is published at /.well-known/security.txt.
Microsoft Store is the distribution channel for REQVERA on Windows.
Windows 10/11 x64 · 6 interface languages · Version 7.3.0.0
Show assurance notes
Assurance notes
Important limits, kept explicit.
- No SOC 2 or ISO 27001 certification is claimed.
- REQVERA does not independently certify GDPR or legal compliance.
- No claim is made that every endpoint compromise or disclosure can be detected.
- Source-level evidence is not a substitute for validating the final signed installed package.