Home/Security & trust
We touch your code, your environments and your evidence. Here is exactly how.
A QA partner sees more of your system than most vendors: source, staging, test data, screen recordings of every failure. This page sets out what we access, where it lives, how long we keep it, the standards we benchmark our controls against, and what we hand your security team for their review.
Principles
Four rules every engagement runs on.
Least access, named people
Only the named engineers on your engagement get access, only to the repositories and environments in scope, through your identity provider where possible. Access is revoked within 24 hours of a role change.
Your environment first
Tests run in your pipeline and against your staging by default. Production is touched only with written authorisation, on read-only or synthetic paths, with test payment methods.
Evidence is personal data until proven otherwise
Videos, traces and HAR files can capture screen content. We treat them as confidential, store them encrypted, keep them for 90 days by default, and delete on request.
Nothing without authorisation
Load rehearsals, production runs and any change to scope are agreed in writing, scheduled with your platform lead, and logged.
Data handling
What we access, where it lives, how long we keep it.
| Data | What it is | Where it lives | Retention | Who can access |
|---|---|---|---|---|
| Source code | Read access to the repositories in scope; generated tests submitted as pull requests | Your source-control provider. No long-lived clones outside CI runners. | Nothing retained after a run completes | Named engineers on your engagement; revocable by you at any time |
| Environments & secrets | Staging URLs, test accounts, CI secrets | Your vault or CI secret store. We never store customer credentials in plain text or in tickets. | Deleted at engagement end; rotated on request | Named engineers; access reviewed quarterly |
| Test evidence | Videos, Playwright traces, HAR files, console logs for failures | Encrypted storage in the region agreed in your SOW, or your own storage if you prefer | 90 days by default; configurable; deleted on request | Your team and your named engineers; access logged |
| Load-test data | Synthetic users, synthetic orders, test payment methods | Generated for the rehearsal; runs scheduled to avoid real users | Aggregated results kept with the report; raw runs purged after 30 days | Your platform lead and your named engineers |
| Reports & verdicts | Coverage maps, go/no-go verdicts, trend reports | Delivered to you; a copy retained for the engagement record | Duration of the engagement plus 12 months, unless you ask for earlier deletion | Your stakeholders; your named engineers |
| Business contacts | Names, work emails, roles of the people we work with | Our business systems | Per the Privacy Policy | Engagement and account staff |
Production personal data is never copied into test systems. Where a test must use production-like data, we use synthetic or pseudonymised datasets agreed with you.
Controls
Operational and technical controls, by domain.
- Multi-factor authentication on every system that touches customer data
- Named accounts only — no shared logins; least privilege by engagement
- Quarterly access reviews; offboarding within 24 hours
- TLS 1.2+ for all data in transit
- Encryption at rest for hosted evidence and reports
- Keys managed by the cloud provider's key service; customer-managed keys on request
- Peer review on every change to the platform; dependency and secrets scanning in CI
- Platform tested against the OWASP Top 10; OWASP ASVS Level 2 as the target
- Customer-led penetration tests of the platform welcomed with notice
- Patching targets: critical within 7 days, high within 30 days
- Hosts and containers hardened against CIS Benchmarks
- Responsible-disclosure channel below
- Documented incident process with a named owner
- Customers notified within 48 hours of confirming an incident affecting their data — inside GDPR's 72-hour and India DPDP's "without delay" windows
- Post-incident report with root cause and corrective actions
- Every engineer under written confidentiality obligations; security training at onboarding and annually
- Background verification where local law permits
- Backed-up engagement records; documented continuity plan for peak-day standby
Security benchmarking
The standards we measure ourselves against.
We map our controls to the frameworks your security team already uses, and hand you the mapping rather than a badge. Where we are working towards a certification, we say so plainly.
- ISO/IEC 27001:2022 — Annex A control mapping available on request; certification on the roadmap.
- SOC 2 Trust Services Criteria — security, availability and confidentiality criteria mapped; Type II report on the roadmap.
- OWASP ASVS Level 2 and OWASP Top 10 — for the Zenius platform itself.
- CIS Benchmarks — hardening baseline for hosts and containers.
- NIST Cybersecurity Framework 2.0 — programme structure: identify, protect, detect, respond, recover.
- GDPR, UK GDPR, CCPA/CPRA, India DPDP Act 2023 — see the Privacy Policy and DPA.
- WCAG 2.2 AA — accessibility target for this site and the platform UI.
For your review
What we hand your security and legal teams.
Your questionnaire, completed
SIG Lite, CAIQ, or your own format, answered by the people who run the controls — not a sales deck.
DPA, SCCs, control mapping
Data Processing Addendum with EU Standard Contractual Clauses and the UK Addendum, the sub-processor list, and the ISO 27001 / SOC 2 control mapping.
Architecture, data flows, test results
Data-flow diagram for your engagement, platform architecture, and penetration-test summaries as they are completed. Annual right to audit in the MSA.