Encryption Everywhere
- TLS 1.3 for all data in transit
- AES-256 encryption at rest
- HMAC-signed session tokens
- Scrypt password hashing with unique salts
Security
Test plans, bug reports, and quality metrics are sensitive intellectual property. We protect them with the same rigor that enterprise organizations expect — encryption, isolation, access controls, and full auditability.
Security Architecture
Development Practices
All database queries use parameterized statements. Input validation via Zod schemas. No string interpolation in SQL. Content Security Policy headers on all responses.
Dependencies are pinned to exact versions. Automated vulnerability scanning on every build. Critical patches applied within 24 hours of disclosure.
Automated daily backups with point-in-time recovery capability. Backup integrity verified regularly. Recovery procedures tested quarterly.
Documented incident response procedures. Affected users notified within 72 hours of confirmed breach. Post-incident reviews with published findings.
No third-party advertising trackers or pixels
No selling or sharing of customer data
Data export available at any time, in standard formats
Account deletion with complete data removal within 30 days
Minimal cookie usage (session auth only)
Rate limiting and brute-force protection on all endpoints
Security headers (CSP, X-Frame-Options, HSTS) on all responses
Regular security reviews and code audits
We take security seriously. If you've found a vulnerability or have security-related questions about our platform, please reach out.
See also: Privacy Policy