Security

Security that holds up under scrutiny.

BeyondTest is used for regulated and safety-critical testing, so the product is built around isolation, traceability and keeping your data under your control. Here is exactly how that works today — no vague promises.

Isolation & data ownership

The core of our model: your data lives on your instance, and AI runs on your key.

One dedicated instance per customer

Every customer runs on their own isolated instance with its own database. There is no shared multi-tenant table your data sits in alongside anyone else's — isolation is at the instance boundary, not a WHERE clause.

Your AI, your key

AI runs on your own provider key — Anthropic Claude, OpenAI, or Google Gemini. Your requirements and test data go only to the model provider you choose, under your account. They never pass through a shared BeyondTest AI service, and they are never used to train a vendor's model.

Data residency on request

Because each instance is dedicated, we can place yours in the region you need. Ask us during onboarding.

Data protection

How data is protected in transit, at rest, and in backups.

Encryption in transit

All traffic is served over HTTPS/TLS. Plain-HTTP requests are redirected to TLS.

Secrets encrypted at rest

Sensitive settings — your AI provider key and integration tokens (e.g. Jira) — are encrypted with AES-256-GCM before they are stored. Plaintext keys are never written to the database.

Passwords are hashed

Account passwords are hashed with bcrypt and never stored or logged in plaintext. Sessions use a signed, httpOnly, secure cookie.

Encrypted, scheduled backups

Automated backups run on a schedule to a destination you control — a folder on the instance or your own S3 bucket — with configurable retention. Your data isn't copied to a BeyondTest-owned store.

Access & accountability

Who can get in, what they can see, and a record of what happened.

Single sign-on

Sign in with your identity provider over OIDC, so account lifecycle and MFA stay governed by your IdP.

Role-based & per-product access

Admin, manager and member roles, plus per-product access control, so people only see the products they're assigned to.

Complete change history

Changes to requirements, cases and runs are recorded, and requirement sign-offs are captured as version-pinned e-signatures — so you can always show exactly who approved what, and when.

Compliance & questionnaires

BeyondTest is an early-stage product, and we're direct about where we are: the platform is designed to support the traceability, sign-off and record-keeping requirements of standards like IEC 61508, ISO 26262 and IEC 62304, but BeyondTest itself does not yet hold a formal certification such as SOC 2. If your procurement process needs a security questionnaire completed, or you want to discuss a specific control or our certification roadmap, we'll work through it with you directly.