Skip to main content
All internet-facing TestDino services and their security configuration.

Quick Reference


Core Services

Authentication & Billing

Integration Services

Internal Services

Network & Security

CORS

The API enforces strict CORS policies:
  • Only explicitly configured origins are allowed (no wildcard *)
  • Origins are defined per environment via CORS_ORIGIN configuration

TLS

  • All endpoints enforce HTTPS (TLS 1.2+)
  • HTTP requests redirect to HTTPS
  • Certificates are managed via hosting infrastructure

Rate Limiting

Security Headers

All responses include headers via Helmet:
  • Content-Security-Policy (CSP)
  • X-Frame-Options
  • X-Content-Type-Options
  • Strict-Transport-Security (HSTS)

Firewall Configuration

If your organization uses network-level allowlisting, add these domains: Review what data is collected and how long it is retained.

Access to Customer Data

Full list of data TestDino collects

Data Retention

Retention periods by tier and data category