Where things run
- Application and database: Render.com, Virginia (United States). PostgreSQL, encrypted at rest by the provider.
- Test execution: your flows run in Chromium (Playwright) on a worker in the same Render region. One browser at a time per worker; nothing runs on your machine.
- Screenshots and videos: Cloudflare R2 object storage, served only through the application to signed-in members of your account.
- Email: Resend. Payments: Paddle as Merchant of Record; we never see or store card numbers.
- Outbound IP addresses: if your staging environment is behind an IP allow-list, email hello@horusqa.ai and we will send you the current addresses of the test workers.
What we store about your tests
- The recorded steps: URLs, element selectors, typed values and assertions. If you type a real password into a recorded flow, it is stored as a step value; use test credentials.
- Per-step results, a screenshot per step and a video per run.
- Retention while active: test results 90 days (Trial), 180 days (Starter) or 1 year (Pro, Business); screenshots and videos 7, 30 or 90 days respectively.
- After a subscription ends: runs, screenshots and videos are deleted 60 days later, with a reminder one week before. Flows and projects are kept until you delete the account.
- Account deletion removes everything within 30 days. You can export any flow to CSV or Gherkin at any time.
Access and transport
- TLS on every connection, including between the application and storage.
- Passwords hashed with bcrypt. Sessions expire after 24 hours of inactivity.
- Row-level isolation: every record belongs to one account and every query is scoped to it. Roles: owner, admin, member.
- API tokens are stored as SHA-256 digests; the plain token is shown once. Requests are rate-limited.
- Billing webhooks are HMAC-signed and rejected when stale; outbound notification URLs must be public HTTPS hosts.
- Dependencies are audited and the code scanned for vulnerabilities on every change.
What we do not have
No SOC 2 report, no ISO certification, no contractual SLA, no SSO or SCIM, no EU data residency. We are a small team and say so up front; if any of these is a requirement, tell us and we will be honest about timelines.
Reporting a vulnerability
Email legal@horusqa.ai. We acknowledge reports within three business days and do not pursue researchers who act in good faith.
See also the Privacy Policy and Terms of Service.