1. Compliance, Audits & Certifications
Security is built into every component of AspectIQ. We maintain robust compliance frameworks audited by independent third-party assessors to guarantee our controls meet the highest industry standards:
- SOC 2 Type II: We undergo annual SOC 2 audits covering security, availability, and confidentiality. Reports are available to enterprise customers under NDA.
- ISO 27001:2022: Our Information Security Management System (ISMS) is certified by accredited registrars, covering all product engineering, support operations, and platform hosting environments.
- PCI-DSS Readiness: Our environment meets the requirements for PCI-DSS Level 1 compliance. We do not store credit card credentials directly; payment operations are handled by Stripe.
2. Data Protection & Encryption
We ensure that your application metadata, test runs, and credentials are protected at every stage:
Encryption in Transit: All data transmitted to or from the AspectIQ cloud console is encrypted using TLS 1.3 with strong cipher suites.
Encryption at Rest: Customer datasets, trace files, and repository credentials are encrypted using AES-256-GCM. Decryption keys are managed and rotated securely using hardware security modules (HSMs).
3. Network & Infrastructure Security
Our platform runs on industry-leading cloud infrastructure (AWS/Google Cloud). We isolate services using Virtual Private Clouds (VPCs), strict firewall policies, and intrusion detection systems:
- Environment Isolation: Each enterprise customer is assigned a logically isolated tenant partition to prevent cross-contamination of execution threads.
- DDoS Mitigation: We utilize advanced traffic scrubbers and Content Delivery Networks (CDNs) to shield our APIs from denial-of-service attempts.
- Agent Security: Local testing agents communicate exclusively via outgoing HTTPS ports, removing the need to open inbound firewall ports in your enterprise network.
4. Access Controls & Authentication
We operate on a zero-trust model internally and provide security controls for your team:
- Granular RBAC: Define exactly who can edit test paths, view test runs, or modify billing configurations with Role-Based Access Control.
- Single Sign-On (SSO): Integrate your identity providers (SAML 2.0, OIDC) including Okta, Azure AD, and Ping Identity.
- Multi-Factor Authentication: Mandate MFA (OTP, security keys) across your entire workspace to prevent credential stuffing attacks.
5. Vulnerability Management
We maintain an active security review schedule to locate and patch anomalies:
Static & Dynamic Scanning: Our CI/CD pipelines run automated static analysis (SAST) and software composition analysis (SCA) to identify package dependencies with known vulnerabilities before code reaches production.
Penetration Testing: We hire independent CREST-accredited security firms to perform comprehensive gray-box penetration tests on our platform annually.
6. Incident Response & Disaster Recovery
We are prepared to respond to emergencies quickly and transparently:
Monitoring: Our security operations center (SOC) monitors logs, anomaly alerts, and threat vectors 24/7/365.
Response SLA: In the event of a confirmed data breach, AspectIQ commits to notifying affected customers within 72 hours of identification, providing detailed impacts and mitigation instructions.
Disaster Recovery: Workspace data is backed up daily and replicated across multiple availability zones. We run mock recovery drills quarterly to verify RTO/RPO expectations.
7. Physical & Datacenter Security
AspectIQ SaaS services are hosted in SOC 2 and ISO 27001 certified datacenters operated by Amazon Web Services and Google Cloud. These locations feature strict physical access controls, including biometric scanning, perimeter fencing, security patrols, and continuous video logging.
8. Contact Security Team
If you discover a security vulnerability or have questions about our security practices, please contact our security team at security@aspectiq.ai. We host a private bug bounty program and appreciate responsible disclosures.