Test runs are sensitive by default.
Smoketest runs AI-assisted browser tests against software you own or are authorized to test. Because runs can capture app screens, credentials, and customer-like data, we treat test execution and artifacts as sensitive by default.
What we do with your data.
The controls that are live today. Not a promise of future work, and not a contractual guarantee; the DPA is.
Credential encryption
Customer environment variables, credentials, HTTP basic-auth passwords, and Jira or Linear OAuth tokens are encrypted before storage using AES-256-GCM.
Verified Jira and Linear events
Provider signatures or verification tokens are checked before accepted Jira or Linear webhook events are normalized and processed.
Artifact access
Run recordings, screenshots, traces, transcripts, and debug artifacts are treated as sensitive customer content, stored in Smoketest-controlled artifact storage, and served through signed URL access.
90-day artifacts
Run artifacts stored in Cloudflare R2 are covered by a 90-day lifecycle deletion policy.
EU infrastructure
The application, API, worker, Postgres, Redis, and server backups run on a Hetzner server in Germany.
Monitoring
Operational logs are drained to Grafana Cloud for monitoring, debugging, reliability, and incident response.
Secret-aware logs
API logging redacts authorization and cookie headers, and agent events redact known sensitive environment values.
Bounded issue images
Issue images are limited to supported HTTPS image types, 5 MB per image and 10 MB per Attempt, with authorization scoped to the provider host and unsafe redirects rejected.
What we ask of you.
- 01Use dedicated test accounts instead of real user credentials whenever possible.
- 02Prefer test environments, test data, and scoped credentials over production secrets.
- 03Avoid putting unnecessary personal data, payment card data, health data, government IDs, secrets, or other highly sensitive data into Tests, issue descriptions, comments, attachments, or linked pull requests used by Smoketest.
- 04Only test systems, environments, and accounts you own or are authorized to test.
- 05Grant Jira, Linear, and GitHub only the scopes and workspaces needed for the projects you connect.
- 06Review Slack or Discord notification settings before sending failure summaries into shared channels.
Where the line is.
AI-assisted runs and results may be incomplete or incorrect. AI-generated outputs and results are informational only and are not security audits, penetration-test reports, legal assessments, or professional opinions of any kind.
Smoketest supplements but does not replace human QA, security review, legal review, accessibility review, or monitoring. The security controls described on this page represent our current practices and are not contractual guarantees. No system can be guaranteed perfectly secure.
Deletion is currently handled manually. Contact [email protected] for account, workspace, run, or artifact deletion.
Who else touches the data.
Smoketest uses a focused set of infrastructure, AI, email, billing, analytics, monitoring, authentication, Jira, Linear, repository, and optional notification providers. Browser Use handles cloud browser execution and provider recording processing. Cloudflare R2 stores Smoketest-controlled run artifacts after recordings are downloaded into our artifact storage.
The DPA has the detailed subprocessor table and processing terms, including what each provider receives and where it runs.
Subprocessor table in the DPAFound something?
Report vulnerabilities or security concerns to us directly. Privacy requests go to [email protected].Last updated August 5, 2026.