Encryption
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Encrypted database backups
- Secure key management with rotation policies
Access Control
- Role-based access control (RBAC)
- Multi-factor authentication support
- Session timeout and single active session enforcement
- Principle of least privilege for all internal systems
Infrastructure
- Hosted on enterprise-grade cloud infrastructure
- Isolated environments per customer (logical separation)
- Automated daily backups with point-in-time recovery
- DDoS protection and rate limiting
Exam Integrity
- Secure browser mode with full-screen lockdown
- Tab-switch and focus-loss detection
- Copy/paste and DevTools blocking
- Auto-submit on critical violation threshold
Monitoring & Auditing
- Real-time anomaly detection and alerting
- Comprehensive audit logs for all admin actions
- Uptime monitoring with automated incident response
- Regular penetration testing and vulnerability scans
Organisational Security
- Security awareness training for all staff
- Background checks for employees with data access
- Documented incident response and breach notification procedures
- Vendor risk assessments for all sub-processors
Responsible Disclosure
If you discover a security vulnerability in TestPilot, we ask that you report it responsibly. We commit to acknowledging your report within 48 hours and working with you to resolve the issue promptly.
Report a Vulnerabilitysupport.testpilot@gmail.com