TestDino

Security and compliance at TestDino

Earning your trust with independently audited controls, encrypted data, and a security program built for Playwright teams that ship to production.

Last updated: September 2026

TestDino, operated by Alphabin Technology Consulting, holds an unqualified SOC 2 Type 2 opinion against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality. We are also ISO 27001 certified and GDPR compliant. The product in scope is the TestDino test intelligence and observability platform for Playwright teams.

Independent Audits and Certifications

SOC 2 Type 2

Certified

SOC 2 Type 2 Certified

TestDino achieved SOC 2 Type 2 compliance in March 2026, independently audited by Percilchofe CPA LLC against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality.

  • Observation period: December 1, 2025 to February 28, 2026
  • Unqualified opinion across all tested controls
  • Trust Service Criteria: Security, Availability, Confidentiality
  • Available under NDA

ISO 27001

Certified

ISO 27001 Certified

TestDino operates an Information Security Management System (ISMS) certified to the ISO/IEC 27001 international standard, covering risk management, controls, and continuous improvement.

  • Risk-based information security management
  • Annual surveillance and recertification audits
  • Certificate available on request

GDPR

Compliant

GDPR Compliant

TestDino processes personal data in line with the EU General Data Protection Regulation. We sign Data Processing Agreements with customers and provide standard contractual clauses for international transfers.

  • Data Processing Agreement available on request
  • Standard Contractual Clauses for EU/EEA transfers
  • Right to access, rectification, erasure, and portability

Our security controls follow ISO/IEC 27001, the standard India's Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 recognise as reasonable security practice under section 43A of the Information Technology Act, 2000.

SOC 2 Type 2 reports and ISO 27001 certificates are shared under a mutual NDA. We respond to access requests within two business days.

How Customer Data Is Protected

  • Production databases are isolated within a private virtual network and not exposed to the public internet.
  • Customer data is removed from TestDino systems on request or per contractual terms.
  • Test artifacts and metadata are scoped to the customer that uploaded them and not shared across tenants.

Encryption in Transit and at Rest

  • Customer-facing traffic is served over HTTPS with TLS 1.2 or higher.
  • Data at rest in our Azure databases and object storage is encrypted using Azure platform encryption (AES-256).
  • Encryption keys are managed by Azure Key Management with rotation handled by the platform.

Who Can Access Your Data

  • Customer test data and traces are not browsed by TestDino staff in normal operation.
  • Support engineers can access a customer's test data only after the customer grants permission through a support ticket, and only for the duration needed to resolve the issue.
  • Production access is restricted to a small number of engineers on a need-to-know basis under role-based access control.
  • Access to customer data is logged.

AI Processing and Your Test Data

  • AI features use Microsoft Azure OpenAI Service and Azure AI Foundry, hosted within our Azure tenant. They are listed on our Subprocessors page.
  • Microsoft does not use Customer Content sent through Azure OpenAI to train its foundation models, in line with the Azure OpenAI Service terms.
  • We do not train TestDino-owned models on customer data by default. If a customer opts in to contribute test data, the scope is documented in writing and the opt-in can be revoked at any time.
  • Enterprise customers can disable AI-powered features for their workspace.
  • AI processing of customer data is covered by our Data Processing Agreement.

Internal Access Control

  • Role-based access with least-privilege defaults across the production environment and source code.
  • Access is reviewed at planned intervals and revoked when an employee or contractor leaves.

Authentication and Secrets

  • Sign-in is handled by Azure AD B2C. We never build or store our own credential system.
  • Passwords are never stored in plaintext. Secrets are encrypted and access is restricted on a need-to-know basis.

Where TestDino Runs

  • Hosted on Microsoft Azure, our SOC 2 audited subservice provider for data center services.
  • Production systems sit behind a virtual private cloud with security groups acting as virtual firewalls.
  • Infrastructure changes follow a documented SDLC with peer review and automated checks before release.

Resilience and Recovery

  • Azure provides redundant power, networking, and storage at the data center level.
  • We maintain a disaster recovery plan covering data restoration and service recovery from backups.

Backup Strategy and Monitoring

  • Databases and object storage are backed up daily, encrypted, and held in a separate Azure region.
  • Backups are encrypted at rest and stored separately from production systems.
  • Production systems are monitored with alerts on availability, error rates, and security events.

Service Status

We publish live service availability and incident history on our public status page. Subscribe to get notified about scheduled maintenance and unplanned incidents.

View status: testdino-uptime.instatus.com

Operational Security

  • Documented incident response process with defined roles, escalation paths, and customer notification.
  • Confidentiality and acceptable-use obligations apply to everyone with access to customer data.
  • Security events surfaced by monitoring are triaged and tracked through to resolution.

Incident and breach notification

If a security incident affects your data, we notify affected customers without undue delay, with what we know about the scope, the data involved, and the steps we are taking. Where India's Digital Personal Data Protection Act, 2023 applies, we also report the breach to the Data Protection Board of India and to affected individuals in the form and within the time the Act and its Rules require. Where a United States state breach-notification statute applies, notice follows that state's timeline. Contractual notification windows agreed in a Data Processing Agreement take precedence where they are shorter.

Responsible Testing Guidelines

We support good-faith research and will not pursue legal action against researchers who follow these guidelines. To protect customer data and service availability, please do not:

  • Run denial-of-service or distributed denial-of-service (DDoS) attacks of any kind, including brute-force or automated traffic floods.
  • Social engineer TestDino employees, contractors, customers, or vendors. This includes phishing, vishing, and physical intrusion attempts.
  • Access, modify, exfiltrate, or destroy data that does not belong to you, or pivot beyond what is needed to demonstrate the issue.
  • Test on production accounts other than your own. Use a dedicated test account where possible.
  • Run automated scanners that generate large amounts of traffic against the production environment.
  • Publicly disclose, share, or sell vulnerability details before we have confirmed a fix and agreed on a disclosure timeline.

If a test could affect other users or production stability, contact us first at [email protected] so we can coordinate.

Reporting Security Issues to TestDino

If you believe you have found a security vulnerability in TestDino, email [email protected] with reproduction steps, affected endpoints, and any proof-of-concept material. For sensitive reports, request our PGP key by emailing [email protected] so you can encrypt the report in transit.

We acknowledge new reports within two business days. After acknowledgment, we ask you to keep details confidential for up to 90 days while we investigate and ship a fix. If we need more time, we will coordinate an extended timeline with you in writing. Once a fix is confirmed, you are free to publish.

For privacy and data-handling questions, see our Privacy Policy and GDPR page.

Contact Our Security Team

We answer security mail within two business days at [email protected].