Security & data handling
QA work means access to your product before your users see it. Here is exactly how we treat that responsibility — stated plainly, so you can evaluate it.
Your session artifacts
- Encrypted in transit and at rest. All traffic is TLS; recordings, screenshots, and notes are stored in encrypted object storage.
- Access-controlled. Artifacts live behind authenticated, organization-scoped accounts. Only your engagement's QA owner and the people you authorize can view them.
- Retained on your schedule. Retention is agreed per engagement; artifacts are deleted on request, and everything we produce is yours to keep or take elsewhere.
Access to your product
- Least-privilege credentials. We test with QA-scoped accounts you provision — never shared admin logins.
- Staging-first. We test against the environment you designate. Production passes happen only where you direct them, with the constraints you set.
- No surprise mutations. Test data conventions (accounts, records, cleanup) are agreed before the first session.
AI processing
- Session artifacts are analyzed with models from Anthropic, OpenAI, and Google via their commercial APIs, which do not use API inputs to train models.
- Every AI-surfaced finding is verified by a human before it reaches your tracker.
Compliance posture
We are a young company and we will not pretend otherwise: we do not yet hold a SOC 2 attestation. What we offer today, honestly:
- This page as a standing, accurate description of our controls — it changes when our practices change.
- We will complete your security questionnaire and sign an NDA and data processing agreement as part of any engagement.
- Scoped engagements for regulated teams: staging-only access, synthetic test data, and shortened retention are all available.
Reporting a concern
Found a vulnerability or have a security question? Email hello@agentdesigncheck.com — security mail is read first, and you'll get a human reply within one business day.