Security

Last updated: June 2026

Security is built into TestSurge from the ground up. Here's how we keep your test data, story content, and account safe.

SOC2 Ready

TestSurge's infrastructure and processes are built to SOC2 standards covering security, availability, and confidentiality. We undergo regular internal audits and are preparing for formal SOC2 Type II certification as we scale.

SSO / Google Workspace

Enterprise and Team plans support single sign-on via Google Workspace, so your team can log in with existing corporate credentials. SAML-based SSO for other identity providers is available on request.

Role-Based Access Control (RBAC)

Admins can assign granular roles — Admin, Editor, Viewer — to control who can generate, edit, export, or manage billing. Audit logs track who changed what and when, giving you full visibility into team activity.

End-to-End Encryption

All data in transit is encrypted with TLS 1.2+, and all data at rest is encrypted using industry-standard AES-256. Story content and generated test artifacts are encrypted in our database and backups.

Data never sold

We never sell, rent, or share your story content or account data with third parties for advertising or any other purpose. Your data is used only to provide and improve the TestSurge service for you.

On-Prem Option

For organizations with strict data-residency requirements, TestSurge offers an on-premises deployment option on the Team and Enterprise plans, keeping your story data fully within your own infrastructure.

Found a vulnerability?

We take security reports seriously. If you've found a potential vulnerability, please report it to admin@kynetropo.com and we'll respond as quickly as possible.