Quick Reference
Certifications
TestDino maintains independent third-party certifications covering security, availability, and confidentiality.
A Data Processing Agreement is available for customers who require one. For audit reports or a signed DPA, email support@testdino.com.
Encryption
Customer data is encrypted both in transit and at rest.Hosting and infrastructure
TestDino runs on a SOC 2-audited cloud provider with redundant power, networking, and storage.- Production databases run in private virtual networks and are not exposed to the public internet.
- Automated backups are stored separately from production.
- Incident response procedures are documented and followed for security events.
Access control
Production access follows role-based, least-privilege defaults.- TestDino staff do not browse customer test data or traces in normal operation.
- Support access to a customer account requires the customer’s permission and is logged.
- A customer can request removal of their data per the contractual terms.
Data retention
Free keeps test evidence and test history for 7 days. Paid plans keep evidence for 21 days and history for 90 days. Trends and analytics run from 1 month on Free to custom on Enterprise. The full matrix, manual test record caps, and storage quotas are on Retention and Limits.Sensitive Data Scrubbing
TestDino scans test artifacts for secrets and replaces them with masked values before they appear in the dashboard. Scrubbing happens on upload, not on display, so secrets never reach the dashboard at all.NoteSensitive Data Scrubbing is an Enterprise plan feature. Contact support@testdino.com to enable it.
Matches are replaced with
********* across traces, console output, test step errors, network logs, and inline attachments. Test titles, file paths, git metadata, and timing data are left as they are.
What gets scrubbed
Originals are kept encrypted with AES-256, restricted to designated security administrators, and opened only during a security investigation. Every access is logged.
Application logs are scrubbed separately at the infrastructure level on all plans: passwords, tokens, and API keys are stripped, and audit logs record user ID, action, resource, and IP address.
Data removal
Export your data at any time through the dashboard or the API. When a subscription ends, data stays available for 30 days, then is deleted. Deletion requests during the term are handled per your contract. Data that reaches the end of its retention period is deleted automatically, and expired test runs cascade to their suites, cases, and stored artifacts.AI controls
AI features run on enterprise AI providers under contractual terms that prohibit training their models on customer content. AI processing is controlled per project. A master toggle controls all AI analysis at once, and 5 features toggle independently, so you can keep failure categorization on while turning off everything else. With a toggle off, no test data is sent to AI models for that feature.
Configure these in Project Settings. Changes apply from the next test run, and only Owner and Administrator roles can modify AI settings. Disabling AI does not affect existing AI-generated data from previous runs.
Report a vulnerability
Report suspected vulnerabilities to support@testdino.com. Reports are acknowledged within 2 business days. TestDino requests 90 days of confidentiality while a fix is developed and released.Related
What Data We Access
Every data category collected during test execution, registration, and platform usage
Network Endpoints
Internet-facing services, domains, and firewall rules
For security or data privacy inquiries, email support@testdino.com or use the discord community.