Security & trust

Security is the foundation, not a tier

BugBrain is built with tenant isolation, encryption, and least-privilege access from day one. The same controls protect every plan, free or paid.

GDPR CompliantEU data-protection ready. See our Privacy Policy
Controls

What protects your data

Every control below is implemented in the platform today, applied to every organization on every plan.

Per-organization isolation

Every database query is scoped to your organization at the ORM layer. Tenants can never read each other’s data, because the isolation is enforced by code, not convention.

Encryption at rest

Stored credentials are encrypted with AES-256-GCM, and passwords are hashed with argon2id. Sensitive fields are redacted from every log line.

Least-privilege access

API keys are scoped to exactly the permissions you grant, admin actions are fully audited, and every key is individually attributable and revocable.

SSRF-guarded outbound

Every outbound webhook and integration call passes a DNS-resolving safety check, defeating SSRF and DNS-rebinding against internal or metadata endpoints.

Hardened by default

Strict content-security policy, signed and replay-protected webhooks, and brute-force-throttled logins ship on day one, not behind a paid tier.

Auditability

Sensitive operations are written to an audit log, so privileged actions are traceable and attributable across your organization.

Data handling

Your data, on your terms

You decide what gets tested

You choose the apps, environments, and credentials BugBrain uses. You can delete your account and associated data at any time.

Credentials stay protected

Test credentials are encrypted at rest, never written to logs, and used only to run the tests you configure.

Compliance evidence, for you

BugBrain’s compliance and accessibility tooling helps you assemble ADA / WCAG 2.2, SOC 2, and GDPR evidence for your own product from your test runs.

Responsible disclosureFound a security issue? We appreciate responsible disclosure. Email info@bugbrain.tech and we’ll respond promptly.
FAQ

Security questions, answered

Is BugBrain secure?

Yes. Every organization gets tenant isolation enforced at the ORM layer, AES-256-GCM encryption for stored credentials, argon2id password hashing, least-privilege scoped API keys, SSRF-guarded outbound calls, audit logging, and hardened defaults. All of it ships on every plan, free or paid.

How does BugBrain protect my test credentials?

Test credentials are encrypted at rest with AES-256-GCM, redacted from every log line, and used only to run the tests you configure. You choose which apps, environments, and accounts BugBrain can access.

Can other organizations see my data?

No. Every database query is automatically scoped to your organization at the ORM layer, so tenants can never read each other’s data. The isolation is enforced by code, not convention.

Is BugBrain SOC 2 certified?

BugBrain is not currently SOC 2 certified. The platform does implement the underlying controls, including tenant isolation, encryption at rest, least-privilege access, and audit logging. Its compliance tooling also helps you assemble SOC 2, ADA / WCAG 2.2, and GDPR evidence for your own product from your test runs.

How do I report a security vulnerability?

Email info@bugbrain.tech. We appreciate responsible disclosure and respond promptly.

Security you can build on

Start free and put BugBrain to work on your app today.

14-day free trial on Launch · No credit card · Plans from $49/mo