Legal

Security and Data Protection

Effective · July 21, 2026

Introduction

URIQA is designed to help users organize and analyze research and technical project information.

Protecting that information is important to us. Security is also an ongoing process rather than a guarantee. This page explains URIQA's current general approach and the responsibilities users share in protecting their information.

Nothing on this page is a certification, warranty, service-level agreement, or promise that a security incident can never occur. URIQA does not claim compliance with or certification under SOC 2, ISO 27001, HIPAA, ITAR, FedRAMP, CMMC, CJIS, PCI DSS, GLBA, FERPA, FDA requirements, 21 CFR Part 11, or any other standard.

How URIQA is currently hosted

URIQA currently uses Lovable Cloud-managed infrastructure for its database, authentication, private file storage, and server-side functions.

Information is organized around authenticated users, workspaces, and projects. Uploaded file binaries are stored separately from structured records such as notes, findings, plans, drafts, AI conversations, and extracted file intelligence.

How access is controlled

URIQA is designed to use authenticated accounts, workspace-level access restrictions, row-level database policies, private storage, time-limited signed file links, and role restrictions for administrative functions.

A signed file link may allow anyone who obtains that link to access the file until the link expires. Do not forward temporary download links.

Sensitive service credentials are intended to remain on server-side infrastructure rather than in browser code.

How AI processing affects data

When you request AI analysis, relevant prompts, files, extracted text, images, spreadsheet data, or project context may be transmitted to an applicable AI provider.

URIQA is not currently represented as an air-gapped, on-premises, zero-retention, customer-managed-key, or region-locked platform. Do not use URIQA for information requiring those protections unless Tupal LLC has agreed to them in writing.

Administrative access

Administrative tools are intended to focus on account metadata, plan and usage information, security events, audit records, and account controls.

Authorized personnel may access private content when reasonably necessary for user-authorized troubleshooting, security investigation, abuse prevention, legal compliance, or operation of the Service. Administrative access should be limited by role and logged where the applicable logging feature has been implemented.

What security cannot guarantee

No online service can eliminate every risk. Credential theft, compromised devices, software vulnerabilities, malicious files, provider outages, configuration errors, unauthorized sharing, and user mistakes can affect security.

Maintain independent backups of important information. Use a unique password, enable multifactor authentication when available, secure the email connected to your account, review permissions, sign out of shared devices, and avoid uploading information that is not needed.

Regulated and restricted use

Unless covered by a separate written agreement, URIQA is not intended for information that requires HIPAA business-associate terms, ITAR handling, CUI controls, FedRAMP authorization, CMMC certification, CJIS controls, PCI DSS storage, classified-system accreditation, validated manufacturing controls, or another specialized compliance environment.

The presence of authentication, encryption, logging, or private storage does not by itself establish compliance with any particular standard.

Reporting a security issue

Send suspected security vulnerabilities or incidents to support@uriqa.ai with the subject "Security Report." Describe the affected feature, approximate date and time, reproduction steps, and potential impact.

Do not access another user's information, alter or destroy data, perform denial-of-service testing, conduct social engineering, or publish sensitive details. This contact method does not authorize security testing or create a bug bounty, payment obligation, response deadline, or service-level commitment.

Security incidents

URIQA may investigate suspected incidents and take actions it considers appropriate, including restricting access, resetting credentials, preserving logs, working with providers, and notifying affected people or authorities when required by law.

The actions taken will depend on the nature of the event, available information, legal obligations, and technical circumstances.