Quick Reference
Core Services
Authentication & Billing
Integration Services
Internal Services
Network & Security
CORS
The API enforces strict CORS policies:- Only explicitly configured origins are allowed (no wildcard
*) - Origins are defined per environment via
CORS_ORIGINconfiguration
TLS
- All endpoints enforce HTTPS (TLS 1.2+)
- HTTP requests redirect to HTTPS
- Certificates are managed via hosting infrastructure
Rate Limiting
Security Headers
All responses include headers via Helmet:Content-Security-Policy(CSP)X-Frame-OptionsX-Content-Type-OptionsStrict-Transport-Security(HSTS)
Firewall Configuration
If your organization uses network-level allowlisting, add these domains:Related
Review what data is collected and how long it is retained.Access to Customer Data
Full list of data TestDino collects
Data Retention
Retention periods by tier and data category