Effective Date: May 1, 2025
This Security & Compliance document is designed for enterprise risk, compliance, and information security teams evaluating Reqase as a secure AI-assisted testing solution. It outlines our architecture, data handling model, compliance posture, and operational security controls.
Reqase is an AI-assisted testing application built on the Atlassian Forge platform.
We enable QA and software teams to generate test cases and documentation using enterprise AI services.
Reqase:
All primary customer data remains within Atlassian Cloud.
Reqase is deployed exclusively within Atlassian Forge and operates without independent infrastructure:
| Layer | Responsible Party |
|---|---|
| Cloud Infrastructure | Atlassian |
| Data Storage | Atlassian |
| Identity & Access | Atlassian |
| Application Logic | Reqase |
| AI Processing | Enterprise AI Provider |
Reqase operates as an application-layer service within Atlassian Cloud.
We do NOT:
To improve user experience and reduce repeated AI requests, Reqase may temporarily cache certain AI-generated outputs within Atlassian Forge managed storage.
This caching:
Reqase does not independently control the underlying database infrastructure and cannot directly access Atlassian's storage layer outside application-level permissions.
All customer data, including any temporary cached data, remains within Atlassian cloud regions as configured by the customer's Atlassian tenant. Reqase does not independently determine or control data residency.
Reqase integrates with enterprise-grade AI providers including:
If customers use their own AI subscription (e.g., Azure OpenAI), processing occurs under the customer's direct contractual relationship with the AI vendor.
Reqase inherits security controls from Atlassian's cloud environment, which maintains certifications including:
As Reqase does not operate independent infrastructure, we do not maintain a separate SOC 2 report.
Although Reqase does not operate its own infrastructure, we maintain internal security practices including:
Under applicable data protection laws:
Reqase does not independently determine:
Application-level temporary caching is purpose-limited and automatically managed.
In the unlikely event of a security incident:
Compared to traditional SaaS providers, Reqase operates with a reduced operational risk profile:
We may revise this Security & Compliance document periodically to reflect evolving best practices or regulatory requirements. Updates will be posted on our official website and Marketplace listing. Continued use of the application after updates constitutes acceptance of the revised version.
If you have any security or compliance-related questions, please contact:
Last Updated: February 2026