Security
How DoesQA protects customer data: what is stored, credentials, UK AWS hosting, encryption at rest, Cyber Essentials, access control, and retention.
DoesQA protects the data you use for testing with UK cloud hosting, encryption at rest, Cyber Essentials controls, and least-privilege access.
For the longer security programme questionnaire, see Security on does.qa.
Certifications
Cyber Essentials
Held
Cyber Essentials Plus
In progress
SOC 2
In progress
ISO 27001
Scheduled for 2027
Leadership reviews and approves security controls and documentation each year.
Where data lives
DoesQA is fully cloud-based. Infrastructure runs on AWS in the UK (eu-west-2).
DoesQA LTD is registered in England and Wales:
Fulford House, Newbold Terrace, Leamington Spa, Warwickshire, United Kingdom, CV32 4EA
The team is remote and UK-based. Samuel Smith (Co-Founder) is the responsible person for IT systems.
Does DoesQA store our data?
Yes. DoesQA stores only what you provide and connect for testing.
That includes the assets you build and the evidence your Runs produce:
Test design
Flows, Elements, Values, Step Groups
Run evidence
Results, screenshots, and video
Account operation
Settings and user access needed to run the product
Secrets you save
Private Values and MFA secrets (hidden in the UI after save)
You choose the URLs, credentials, and application data that enter DoesQA through your Flows and settings. Infrastructure location is under Where data lives.
How DoesQA handles credentials and secrets?
Put secrets in product controls built for them:
Create under Assets → Values with Private value on. After save, the content stays hidden in the UI and still applies when Tests run. You cannot view or edit the secret content again after save.
Avoid using production passwords or tokens. Account access on DoesQA uses unique users, approval for new access, and least-privilege staff access on the DoesQA side. Your team still decides which credentials enter the product. See Shared responsibility.
How data is protected
Customer data is encrypted at rest.
Customer-facing services use authenticated access over HTTPS. Only essential inbound connections are allowed. Broader inbound rules need a documented business case and board-level approval.
Who can access customer data
Staff access follows least privilege: people get only what they need for their role. Founders have access to everything when required for the business.
Accounts are unique and not shared. New access needs approval. Access is removed promptly when someone leaves. Admin accounts are separate, use MFA, and are not used for day-to-day email or browsing.
How long we keep data
Run evidence (results, screenshots, video, and related Run artifacts) is retained for 60 days.
Account assets such as Flows, Elements, Values, Step Groups, and settings stay for as long as the account is active.
DoesQA follows UK GDPR rights, including the right to removal. When removal is requested, DoesQA removes the personal data in scope so that everything covered by the request is taken out of the product.
How Runs stay isolated
Each Test Case runs on a hosted Test Runner. Use product controls when your environments need extra boundaries:
Allow runner and support IPs through your firewall
Block hostnames Runs should not reach
Keep optional AI inside the UK DoesQA footprint
Shared responsibility
DoesQA secures the platform, infrastructure, and the controls described above.
Your team decides what test data enters DoesQA, who has access on your account, which environments you allowlist, and how Values and credentials are managed in Flows.
Related
Last updated