Security at TestFactors

    Our customers hand us test evidence and SAP SuccessFactors configuration that often contains employee data. These are the commitments we make about how we look after it.

    Encryption in transit and at rest

    Traffic to our product and website is served over HTTPS. We require TLS 1.2 or better, older protocol versions are disabled, and HTTP Strict Transport Security is enforced at the edge. At rest, customer data sits on encrypted volumes and in encrypted object storage, and backups are encrypted in the same way.

    Known, single-region data residency

    We serve customers globally, and wherever you are, your data lives in one region rather than being scattered across many. We will always tell you which region that is. Our current hosting region is AWS ca-central-1 in Montreal, with backups held in that same region. Two narrow exceptions are disclosed in our Privacy Policy: transactional email is delivered by a provider in the European Union, and AI inference may use cross-region capacity in the United States.

    Least-privilege access control

    Authenticated requests are authorised against the user's role and their membership of a specific organization, client, and project, with documented exceptions for health checks and reference data. Customers control who is invited and what role they hold. Access to production is limited to the personnel who require it to operate the service.

    Backups and recovery

    Production databases are backed up daily to encrypted storage in the same region. We restore from those backups on a quarterly schedule to confirm they can actually be recovered rather than assuming it. Our most recent verified restore was in June 2026.

    Secure development

    Application changes are made through pull requests. Every pull request and every merge to our main branch runs static security analysis and checks our dependencies against known published vulnerabilities. Dependency advisories are raised automatically and addressed through scheduled update pull requests.

    A short sub-processor list

    We use a deliberately small set of vendors to run the service: cloud hosting, content delivery, email delivery, and AI inference. Where the law requires it, we put written data processing terms in place with them, and we will tell you who they are and what they handle on request. We do not sell or share your personal data, and we do not use it for advertising.

    Reporting a security concern

    If you believe you have found a vulnerability in TestFactors, or you suspect unauthorised access to an account, email [email protected]. We will acknowledge your report and handle it under our internal incident response procedures.

    Please include enough detail for us to reproduce the issue, the affected URL or endpoint, and how you found it. We ask that you give us a reasonable opportunity to investigate and remediate before disclosing publicly, and that testing does not degrade the service or access data belonging to other customers.

    Customers with a suspected incident affecting their own account should use the same address, and should also notify their internal security team.

    Our binding commitments are set out in our Terms of Service and our Privacy Policy. For anything else, see Support.