TestUtopia
SolutionsPricingAboutContact
Trust Center

How we protect your data

A factual reference for security teams. Every control listed here maps to live code or operational practice — not aspirations.

Last updated: August 13, 2026

Sections

01At a glance02Compliance status03Technical controls04Data handling05Subprocessors06Incident response07Request a review

At a glance

HostingContabo — France (EU)
Data residencyEU only
Encryption in transitTLS 1.2+ via Cloudflare and NGINX
Backup encryptionEncrypted client-side (AES-256) before leaving the host
AuthenticationJWT (15-min access, 7-day refresh) + optional 2FA TOTP
Tenant isolationExplicit company_id predicate on every tenant-scoped query
Code executionDocker sandboxes — no network, read-only FS, seccomp, resource limits
Incident contact[email protected] — 24-hour acknowledgement

Compliance status

We're transparent about where we are. The matrix below distinguishes what's in place today from what's on the roadmap. If a buyer requires a formal report we don't yet have, talk to us — we may pursue it sooner.

StandardStatusNotes
GDPRIn place4-category cookie consent, DSAR support, EU-only data residency, DPA available on request.
PCI DSSIn placeInherited — payment data handled exclusively by Stripe Checkout. We never see card numbers.
SOC 2 Type IINot yetNot currently certified. We can share our control summary and complete security questionnaires (SIG Lite, CAIQ-Lite) on request.
ISO 27001Not yetNot currently certified. Many of the underlying controls are already in place; formal certification on roadmap when buyers require it.
External penetration testNot yetAnnual third-party pen test on the roadmap. We respond to coordinated disclosure today (see incident response).

Technical controls

Authentication

  • JWT access tokens with a 15-minute lifetime
  • Refresh tokens with a 7-day lifetime, rotated on use
  • Optional TOTP-based 2FA with device fingerprinting
  • Cloudflare Turnstile bot protection on login, register, and password reset
  • WebAuthn / passkey support
  • SSO: OIDC and SAML 2.0 from the Advanced plan; SCIM 2.0 provisioning from Professional

Authorization

  • RBAC roles: Admin, Manager, Recruiter, Interviewer
  • ABAC: department-based test access scoping
  • Permissions evaluated server-side on every request

Tenant isolation

  • Every tenant-scoped model carries a required company_id
  • Auth middleware derives company_id from the session; every tenant-scoped query filters on it explicitly
  • Wrong-tenant and not-found are indistinguishable — both return 404, so IDs cannot be probed across accounts
  • Two-tenant regression tests cover cross-tenant access attempts, and new by-ID endpoints ship with them

Code execution sandbox

  • Each candidate submission runs in an isolated Docker container
  • No network access from inside the sandbox
  • Read-only root filesystem; writable scratch dir is per-execution
  • Seccomp profiles restrict syscalls
  • CPU, memory, and wall-clock limits enforced per execution
  • Container destroyed after execution completes

Encryption

  • TLS 1.2+ for all traffic (Cloudflare edge + NGINX origin)
  • Backups encrypted client-side (restic, AES-256) before they leave the host
  • Offsite backup storage is EU-jurisdiction object storage
  • Application secrets injected via environment, never committed

Abuse & rate limiting

  • Login / register: 10 attempts per 15 min per IP
  • Forgot password: 3 per hour per IP + 1 per hour per email
  • Public contact form: 3 per hour + 20 per day per IP

Logging & audit

  • Structured request/event logs with request IDs
  • Authentication events logged (login, refresh, 2FA, password reset)
  • Privileged admin actions logged separately
  • Logs retained at the application layer; centralised log retention is on the roadmap

Proctoring (test-taking)

  • Fullscreen enforcement and tab-switch detection
  • Optional periodic screenshots and geolocation
  • Events streamed in real time over WebSocket to recruiter dashboard
  • Candidate consent captured before proctoring activates

Data handling

Residency

Customer data is hosted on Contabo infrastructure located in France, within the EU. We do not replicate customer databases outside the EU. Subprocessor data flows are listed below.

Encryption

TLS 1.2 or higher in transit. Backups are encrypted client-side with AES-256 before they leave the host, and the encryption key never reaches the storage provider. Secrets are managed via environment variables on the host, never committed to source control.

Retention

Customer data is retained for the lifetime of your account. Deletion requests under GDPR are honored within 30 days. Backup snapshots follow a 7 daily / 4 weekly / 6 monthly rotation, so a snapshot may persist for up to six months before it is pruned.

Backups & restore

Automated daily backups of the production database, encrypted client-side and shipped to EU-jurisdiction offsite storage, with random integrity verification on every run. Restores are not assumed to work: a scripted restore test runs on a schedule against a real snapshot, and a missed or failed backup run raises an alert rather than passing silently.

Your rights (GDPR)

You can access, export, correct, or delete your data at any time. See our Privacy Policy for the full list of rights and how to exercise them.

Subprocessors

Third parties we share specific data with to operate the service. Each is bound by a Data Processing Agreement.

VendorPurposeData sharedRegion
StripePayments, billing, taxBilling email, name, payment method (handled entirely by Stripe — we never see PAN)US / EU
Amazon Web Services (SES)Transactional emailRecipient email and message content (verification, invitations, notifications); delivery, bounce and complaint eventsEU (Frankfurt)
Daily.coLive interview videoDisplay name, interview room ID; ephemeral A/V streams during the callEU / US
CloudflareCDN, WAF, Turnstile bot protection, encrypted offsite backup storage (R2)IP address, request metadata, Turnstile challenge tokens; encrypted backup archives we hold the only key toGlobal edge; backups EU jurisdiction
ContaboCompute, database, Redis hostingAll customer data at restEU (France)
SentryApplication error monitoringException stack traces and request metadata; may include user and company identifiersEU (Germany)
Grafana CloudInfrastructure metrics and log aggregationService metrics and container logs, which may contain IP addresses and request metadataEU

We notify customers of material subprocessor changes via email at least 30 days before they take effect.

Incident response & coordinated disclosure

Found a vulnerability? Email us. We acknowledge reports within 24 hours and will not pursue legal action against researchers acting in good faith.

[email protected]

Include reproduction steps. PGP key available on request.

Acknowledge

Within 24 hours

Initial assessment

Within 5 business days

Customer notification

Without undue delay if their data is affected (GDPR Art. 33–34 timelines)

Buying for an enterprise team?

We'll complete your security questionnaire (SIG Lite, CAIQ-Lite, or your own template), share our DPA, and walk your security team through any control in detail.

Available on request: DPA, subprocessor list, GDPR data flow diagram, architecture overview.

Request a security reviewSecurity overviewPrivacy policy
TestUtopia

Advanced technical assessment engine designed for high-precision engineering teams. Curating talent through rigorous data-driven evaluation.

Solutions

  • Solutions
  • Pricing
  • Features

Company

  • About

Support

  • Help Center
  • Contact support

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security
  • Trust Center
Test Utopia Ltd · Razsadnika-Konyiovitsa, Bl. 22, fl. 6, ap. 38, Sofia, 1330, Bulgaria
Reg. No.: 207409973|VAT: BG207409973
[email protected]|+359 886 363 248

© 2026 Test Utopia Ltd. All rights reserved.