Security
Security overview
Last updated: July 2026
You are considering sending us the most sensitive paperwork your company produces. This page describes, in plain language, exactly how those files are handled, which controls we operate today, and which claims we deliberately do not make. If anything here is unclear, ask before you buy: hello@questforgeai.ai.
1. Closed pipeline, no public uploads
- There is no public self-service upload box on this website. Files are exchanged only inside a confirmed engagement, after payment and scope are agreed by email.
- Document processing runs behind operator access controls. The processing endpoints reject any request without a valid operator token, and they are disabled entirely when no operator token is configured.
- Every engagement is processed in its own isolated working folder with randomized job identifiers. Outputs are never published to a public directory.
2. Encryption and transfer
- All traffic to and from questforgeai.ai is encrypted in transit with TLS.
- File transfer methods are agreed per engagement. If your team prefers its own secure transfer channel, we work inside it rather than forcing ours.
- An NDA is available before any file is shared.
3. Retention and deletion
- Uploads and generated outputs are deleted automatically within 30 days. This is an enforced scheduled job, not a manual promise.
- Earlier deletion is available on written request and is confirmed back to you with the deletion date.
- Deletion dates are logged per engagement.
4. AI processing without training
- Draft answers are generated with Anthropic's Claude API using only the documents you supply for your engagement.
- Your documents are not used to train models. API inputs and outputs under Anthropic's commercial terms are not used for model training.
- Questions your evidence cannot support are flagged for your team instead of guessed. Every package passes a human review before delivery.
5. Payments
- Checkout is operated by Paddle as Merchant of Record. Card details are entered on Paddle's PCI DSS compliant checkout and never touch our servers.
- Webhook messages from Paddle are cryptographically signature-verified before they are trusted.
6. Sub-processors
We keep the list short on purpose:
- Render for application hosting.
- Anthropic for AI draft generation, under commercial API terms with no training on inputs.
- Paddle for payments, tax handling, and billing as Merchant of Record.
7. Who you are dealing with
QuestForgeAI is operated by KAMTOBE CREATIONS LIMITED, a company registered in England and Wales, company number 17288786, registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. You can verify the registration on the Companies House public register.
8. What we do not claim
Trust pages usually stop at the good news. Here is the rest, because your security team will ask anyway:
- QuestForgeAI does not currently hold its own SOC 2 or ISO 27001 certification. We are a specialist drafting service, not a certified platform, and we do not imply otherwise.
- The service is deliberately operated as a controlled, human-reviewed workflow rather than an open self-service tool, precisely because your documents are sensitive.
- Outputs are drafts. Final review, approval, and submission always remain with your team.
9. Reporting a concern
Security questions or vulnerability reports: hello@questforgeai.ai. Reports are acknowledged and taken seriously.