Account and workspace access
Supabase authentication, workspace membership checks and administrator permissions restrict access to product and integration data.
This page summarizes controls currently used to operate AlloyQA. It is not a certification or compliance attestation.
Supabase authentication, workspace membership checks and administrator permissions restrict access to product and integration data.
Connected-service credentials are encrypted at rest. The managed runner receives only the credentials or signed URLs required for the active delivery.
Delivery runs on a private managed cloud runner with no public application endpoint. Each job uses a fresh temporary workspace that is removed after the run.
AlloyQA creates pull requests for review and does not deploy changes to production automatically.
AlloyQA stores workflow records and, when generated, screenshots, Playwright traces, console output and verification evidence for review and troubleshooting.
Temporary repository workspaces are removed after each run. Account and stored-data deletion can be requested through a verified support request.
AlloyQA processes relevant account identifiers, Jira ticket content, GitHub repository and pull-request content, generated changes, test output, execution logs and verification evidence. Core providers include Netlify, Supabase, Google Cloud, OpenAI, PostHog and Resend.
See the Privacy Policy for collection, subprocessors, retention and deletion details.
Security, privacy, data-handling and deletion questions can be sent to privacy@alloyqa.com.