Your report files stay on your device.
RegPreflight reviews report files on your device. Raw Rule 605 and Rule 606 report files are not uploaded to RegPreflight for analysis.
On-device review
The files you add are reviewed on your device.
Large-file processing
Large files are handled on the device so the review can remain responsive without sending raw report data to RegPreflight.
File identification
The review package records a unique identifier for each source file so the evidence can be tied back to the exact files reviewed.
Review package
The supervisory PDF and QA data are created on the device. Reviewer details and comments stay on the device until the user downloads the review package.
Hybrid review guidance
RegPreflight sends only a limited set of derived review signals—such as numeric changes, counts, and yes/no indicators—to its control service. Request integrity is protected with a one-time request ID, freshness window, cryptographic request binding, and signed response verification. Raw report files, report text, filenames, customer names, order IDs, venue names, reviewer comments, and other free-form report content are not included.
Protected RegPreflight policy
Prior-period thresholds, routing and payment change decisions, Material Aspects change review, and finding prioritization are evaluated by a versioned RegPreflight-controlled policy service instead of being published in the website code.
KMS-backed policy signature
Production policy responses require a stable AWS KMS Ed25519 signing identity. The private signing key is non-exportable and remains inside KMS; Vercel uses short-lived OIDC credentials to request signatures. Preview environments use an explicitly labeled test signer.
Local files, protected intelligence
The customer report remains on the device while RegPreflight keeps its higher-value review logic in the controlled service.
Current data flow
Raw report files remain on the device. The control service accepts a fixed, validated schema of non-identifying review observations and rejects arbitrary report content. The response is versioned and signed before it is returned to the browser. Production is configured to fail closed if the KMS signing identity is unavailable. RegPreflight does not intentionally send or store raw report files through this control path. Hosting providers may retain ordinary request metadata according to their platform settings.
What firms should still review
- On-device review reduces the need to transmit raw reporting files, but it does not by itself replace a firm's vendor-risk, change-management, access-control, or information-security review.
- RegPreflight's current workflow does not serve as the firm's system of record or replace enterprise retention, access-control, or audit requirements.
- This statement applies to the current RegPreflight workflow.
- Security design does not change RegPreflight's compliance scope or limitations.