Security
Last updated: June 2026
Security is built into TestSurge from the ground up. Here's how we keep your test data, story content, and account safe.
SOC2 Ready
TestSurge's infrastructure and processes are built to SOC2 standards covering security, availability, and confidentiality. We undergo regular internal audits and are preparing for formal SOC2 Type II certification as we scale.
SSO / Google Workspace
Enterprise and Team plans support single sign-on via Google Workspace, so your team can log in with existing corporate credentials. SAML-based SSO for other identity providers is available on request.
Role-Based Access Control (RBAC)
Admins can assign granular roles — Admin, Editor, Viewer — to control who can generate, edit, export, or manage billing. Audit logs track who changed what and when, giving you full visibility into team activity.
End-to-End Encryption
All data in transit is encrypted with TLS 1.2+, and all data at rest is encrypted using industry-standard AES-256. Story content and generated test artifacts are encrypted in our database and backups.
Data never sold
We never sell, rent, or share your story content or account data with third parties for advertising or any other purpose. Your data is used only to provide and improve the TestSurge service for you.
On-Prem Option
For organizations with strict data-residency requirements, TestSurge offers an on-premises deployment option on the Team and Enterprise plans, keeping your story data fully within your own infrastructure.
Found a vulnerability?
We take security reports seriously. If you've found a potential vulnerability, please report it to admin@kynetropo.com and we'll respond as quickly as possible.