AlloyQA
Security

Implemented controls,
plainly described.

This page summarizes controls currently used to operate AlloyQA. It is not a certification or compliance attestation.

Account and workspace access

Supabase authentication, workspace membership checks and administrator permissions restrict access to product and integration data.

Protected integration credentials

Connected-service credentials are encrypted at rest. The managed runner receives only the credentials or signed URLs required for the active delivery.

Private managed runner

Delivery runs on a private managed cloud runner with no public application endpoint. Each job uses a fresh temporary workspace that is removed after the run.

Pull-request review

AlloyQA creates pull requests for review and does not deploy changes to production automatically.

Evidence and operational records

AlloyQA stores workflow records and, when generated, screenshots, Playwright traces, console output and verification evidence for review and troubleshooting.

Workspace cleanup and deletion

Temporary repository workspaces are removed after each run. Account and stored-data deletion can be requested through a verified support request.

Data processing

AlloyQA processes relevant account identifiers, Jira ticket content, GitHub repository and pull-request content, generated changes, test output, execution logs and verification evidence. Core providers include Netlify, Supabase, Google Cloud, OpenAI, PostHog and Resend.

See the Privacy Policy for collection, subprocessors, retention and deletion details.

Contact

Security, privacy, data-handling and deletion questions can be sent to privacy@alloyqa.com.