Security at TestPlanIt
Your test data is critical to your development process.
We take its protection seriously—whether you self-host or use our hosted service.
Infrastructure
Hosting & Infrastructure
Hosted TestPlanIt instances run on dedicated infrastructure managed by our team.
Encryption
Data Encryption
Data is protected both in transit and at rest.
Application
Application Security
Security controls built into every layer of the application.
Product Features
Security Features for Your Team
Security capabilities available on every plan, including self-hosted.
Single Sign-On
Google, Microsoft, Apple, and SAML 2.0 identity provider integration. Included on every plan at no extra cost.
Two-Factor Authentication
TOTP-based 2FA with support for authenticator apps. Organization admins can enforce 2FA for all users.
Custom Roles & Permissions
Define custom roles with granular permissions. Control access at the organization, project, and feature level.
Audit Logs
Track who did what and when, with full before/after change history for compliance and troubleshooting.
API Token Management
Create API tokens with optional expiration dates. Tokens can be scoped and revoked at any time.
Share Link Controls
Share reports via authenticated, public, or password-protected links with configurable expiration and access logging.
Self-Hosted
Self-Hosted Deployments
TestPlanIt is open source and free to self-host. When you run TestPlanIt on your own infrastructure, you have complete control.
- All data stays on your servers—we never have access to self-hosted instances
- Deploy with Docker in your own data center, private cloud, or air-gapped environment
- All security features (SSO, 2FA, RBAC, audit logs) are available with no feature gating
- Configure your own backup schedules, network policies, and access controls
- Connect your own AI providers—including local models via Ollama for complete data privacy
- Source code is publicly auditable under AGPL-3.0 license
Privacy
Data Privacy & Ownership
Your data belongs to you. Period.
Incident Response
Security Incidents
We take a transparent approach to security incidents.
Disclosure Policy
Vulnerability Disclosure Policy
We welcome security research and want to hear about vulnerabilities in TestPlanIt. This policy explains what testing is authorized, what is not, and what you can expect from us.
How to report
Email [email protected] with enough detail for us to reproduce the issue. Helpful reports include the affected version or URL, a description of the vulnerability and its impact, step-by-step reproduction instructions, and any supporting output or screenshots. Please do not open a public GitHub issue for security problems.
Authorized testing
- A self-hosted TestPlanIt instance that you own and operate—test it however you like
- The published source code under AGPL-3.0, including static analysis and local builds
- Our hosted services, only with prior written permission from [email protected] and only within the scope we agree in writing
Not authorized
The following are outside this policy. Engaging in them is a violation of our Terms of Service and will be treated as unauthorized access, not research.
- Testing against our hosted production services without prior written permission, including scanning, fuzzing, and automated vulnerability tools
- Using a trial, demo, or evaluation account as a platform from which to test our systems
- Attempting to access, modify, download, or retain any account, workspace, or data that is not your own, including any attempt to cross tenant boundaries
- Circumventing or defeating authentication, authorization, rate limiting, billing, or plan entitlement controls
- Denial of service, load testing, resource exhaustion, or anything that degrades service for other users
- Social engineering or phishing of our staff, customers, or vendors, and any physical security testing
- Testing third-party services we rely on, such as our payment, identity, and infrastructure providers
Rules for authorized testing
- Stop as soon as you have confirmed a vulnerability. Do not pivot, escalate, or explore further
- If you encounter customer data, personal data, or credentials, stop immediately, do not retain a copy, and tell us in your report
- Do not establish persistence, install backdoors, or leave test artifacts behind
- Use only accounts you created for testing, and only data you created
- Give us a reasonable opportunity to fix the issue before disclosing it publicly. We ask for 90 days, and will work with you if you need a different timeline
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorized, we will not pursue or support legal action against you in connection with it, and we will work with you to understand and resolve the issue quickly. If a third party brings legal action against you for activity conducted in compliance with this policy, we will make it known that your activity was authorized.
This safe harbor does not apply to activity listed under “Not authorized” above. If you are unsure whether something is in scope, ask us at [email protected] before you test.
What you can expect from us
- We acknowledge reports within 3 business days
- We provide an initial assessment, including whether we consider the issue in scope, within 10 business days
- We keep you updated on remediation progress and tell you when the issue is fixed
- We credit reporters who want to be named in our release notes. We do not currently operate a paid bug bounty program
Documentation
Documents Available Upon Request
We can provide the following documents to prospective and current customers evaluating our security posture.
Security Questionnaire
Pre-filled responses to common security assessment questionnaires (SIG Lite, CAIQ, or your custom format).
Data Processing Agreement
DPA covering GDPR and other data protection requirements for customers processing personal data.
Sub-processor List
Complete list of third-party sub-processors with their purpose, data accessed, and location.
Architecture Overview
Technical overview of our infrastructure, security controls, and data flow for security review.
Contact us at [email protected] to request any of these documents.
FAQ
Frequently Asked Questions
Is TestPlanIt SOC 2 certified?
We are not SOC 2 certified at this time. As a growing company, we are building toward formal compliance certifications. We are happy to share our current security controls and practices in detail upon request.
Where is my data hosted?
Hosted customer data is stored in the United States on infrastructure managed by our team. Dedicated tier customers can discuss specific hosting location requirements.
Do you perform penetration testing?
We conduct periodic security assessments of our application and infrastructure. Our source code is also publicly available under AGPL-3.0, enabling community security review.
Can I test TestPlanIt's security myself?
Yes, on an instance you control. Because TestPlanIt is open source, you can stand up your own deployment and test it as aggressively as you like, and we would like to hear what you find. Testing against our hosted services is a different matter and requires our written permission in advance—see our vulnerability disclosure policy above. Unauthorized testing of our hosted services is treated as unauthorized access and will result in account termination.
I found a vulnerability. What should I do?
Email [email protected] with reproduction steps. Do not exploit the issue, do not access data that is not yours, and do not disclose it publicly until we have had a chance to fix it. If you followed our disclosure policy, our safe harbor applies.
Can I run TestPlanIt in an air-gapped environment?
Yes. TestPlanIt can be deployed with Docker in fully air-gapped environments. All features work offline, including AI capabilities when using local models via Ollama.
How do you handle GDPR compliance?
We offer Data Processing Agreements (DPAs) for customers who require them. Self-hosted customers maintain full control over data residency and processing. We collect minimal personal data and use privacy-focused analytics.
Do you support SSO and 2FA on all plans?
Yes. SSO (Google, Microsoft, Apple, SAML 2.0) and TOTP-based two-factor authentication are included on every plan, including self-hosted. We do not charge extra for security features.
TestPlanIt LLC
Questions about security? Reach us at [email protected]
The TestPlanIt software is free and open source under AGPL-3.0.
Last updated: August 2026