How Varqa protects a private document workspace
Last updated 18 September 2026.
This page says how Varqa protects office files in a workspace. It covers sign-in, who can see a file, uploads, mail, activity logs, and optional storage on your own server. It is not a certificate for a hospital or a bank. We do not claim HIPAA, SOC 2, or ISO.
Sign-in
Passwords are stored as a hash, not as the password itself. New accounts need at least 12 characters. You can turn on an authenticator app and backup codes. An admin can require that for everyone, and can turn off password login when company login is on.
Too many failed tries lock the account. You can change your password and sign out everywhere.
Who sees a file
A file is seen by the owner, by people with folder rights, or by a share you create. Roles tick what a person can do. Privilege and restricted flags, classification, and department add extra limits. A legal hold blocks delete and archive.
Uploads and mail
Uploads can be virus-scanned. Mail import can use a sender allowlist. We warn on duplicate files. Background jobs retry if a read fails.
Activity and export
The activity log records views, uploads, searches, chats, and shares. You can export your data. An admin can export data for a person.
Operators
The operator desk is a separate sign-in. It handles walkthrough requests, company pause, Ask credits, and support tickets. Operators do not browse company files from a ticket.
Your own server
You can keep files on the machine that runs Varqa, or on SharePoint or S3. Self-hosting means the file store is under your control. You still choose whether Ask sends text to an AI provider for a written answer.
Common questions
- Can operators open my company files?
- Operators handle walkthrough requests, pause, credits, and tickets. They do not browse company files from a support ticket.
- Can I host files myself?
- Yes. Storage can be this server, SharePoint, or S3. You can run Varqa on your own machines.