How QualityMax protects your repositories, test data, and credentials — written for security reviewers, not marketers.
Short version. We process your data only to run quality workflows you configure. Production data lives in the EU (Supabase), is isolated per tenant via Postgres Row-Level Security, and is never used to train AI models. GitHub/GitLab access is least-privilege OAuth — we do not persist your source code as a standing copy.
PostgreSQL on Supabase managed infrastructure with encryption at rest. API keys and integration secrets are encrypted with Fernet symmetric encryption before storage.
TLS 1.2+ for all client and service-to-service traffic.
Postgres Row-Level Security (RLS) on tenant-bound tables. Cross-tenant reads are blocked at the database layer, not only in application code.
Customer accounts authenticate via Supabase Auth (email/password and OAuth providers such as GitHub) with JWT session tokens. Enterprise plans add SSO / SAML / SCIM (roadmap item for regulated teams — contact us for current availability).
Repository connectors use OAuth 2.0 with the minimum scopes required for the workflows you enable. OAuth tokens are stored server-side and are not exposed through customer-facing APIs.
EU — Supabase managed PostgreSQL (European region).
Operational telemetry and AI workflow traces may be processed by EU-hosted or contractually EU-compliant subprocessors. Enterprise customers can discuss self-hosted or region-locked observability during procurement.
QualityMax reads repository metadata and file contents transiently to generate tests, run scans, and post results back to your CI — we do not maintain a permanent mirror of your codebase.
Customer data and AI-generated test output are not used to train foundation models. If we ever introduce opt-in features that use your data differently, they will be described separately at the point of opt-in.
Test artifacts, run history, and audit logs are scoped to your workspace and retained for your operational and compliance needs. You can request deletion via contact@qualitymax.io or through account settings where self-service export/delete is available.
Browser-based test execution runs in isolated cloud sandboxes with resource limits and automatic teardown. Local execution via qmax-code runs on infrastructure you control.
GitHub App and GitLab integrations request only the permissions needed for the features you enable (e.g. checks, comments, workflow dispatch). Read-only analysis paths do not require write access to your default branch.
API endpoints are rate-limited. Automated abuse detection can temporarily block IPs that exceed fair-use thresholds.
SAST, dependency scanning, and secret detection run as deterministic CI workflows — separate from probabilistic AI review — so security findings do not depend on model hallucination.
Test runs, PR gate decisions, and key workflow events are logged for review inside the product. Enterprise plans add extended audit logs and export.
QualityMax is not currently SOC 2 or ISO 27001 certified. We are preparing controls aligned with SOC 2 Type II expectations and will publish an “in audit” status on this page when a formal audit begins.
For a current subprocessor list and DPA terms, see our Privacy Policy.
No customer-impacting security incidents to report as of July 2026.
For incident-history requests, contact contact@qualitymax.io.
We welcome good-faith security research. Report vulnerabilities to contact@qualitymax.io.
Canonical disclosure file: /.well-known/security.txt
Live service status: qualitymax.io/status. For urgent security questions outside published incidents, email contact@qualitymax.io.
Security contact: contact@qualitymax.io
Response window: Business hours, Mon–Fri (CET). 48-hour triage SLA.
Privacy / GDPR: See Privacy Policy for data-subject requests.