Skip to main content
TestDino is SOC 2 Type 2 and ISO 27001 certified, GDPR compliant, and hosted on Microsoft Azure with encryption in transit and at rest. This page states the certifications, controls, and data-handling practices that back the platform.

Quick Reference

Certifications

TestDino maintains independent third-party certifications covering security, availability, and confidentiality. A Data Processing Agreement is available for customers who require one. For audit reports or a signed DPA, email support@testdino.com.

Encryption

Customer data is encrypted both in transit and at rest.

Hosting and infrastructure

TestDino runs on Microsoft Azure, a SOC 2-audited subservice provider with redundant power, networking, and storage.
  • Production databases run in private virtual networks and are not exposed to the public internet.
  • Automated backups are stored separately from production.
  • Incident response procedures are documented and followed for security events.

Access control

Production access follows role-based, least-privilege defaults.
  • TestDino staff do not browse customer test data or traces in normal operation.
  • Support access to a customer account requires the customer’s permission and is logged.
  • A customer can request removal of their data per the contractual terms.
For the full list of data categories TestDino collects, see Access to Customer Data. For internet-facing services and firewall configuration, see Cloud Endpoints.

AI data handling

AI features run on enterprise AI providers under contractual terms that prohibit training their models on customer content. AI processing is controlled per project. When AI is disabled for a project, no test data from that project is sent to AI models. Configure this with the Enable AI Insights toggle in Project Settings, described in AI Controls.

Report a vulnerability

Report suspected vulnerabilities to support@testdino.com. Reports are acknowledged within two business days. TestDino requests 90 days of confidentiality while a fix is developed and released.

Data Privacy Overview

What data is collected, protected, and retained

Data Retention

Retention periods and GDPR data rights

Data Redaction

How secrets are removed from traces and artifacts

Cloud Endpoints

Internet-facing services and firewall rules