Security policy
Last updated: September 2026
Allure TestOps is designed to collect, organize, and present automated and manual test results and documentation. Customers do not need to upload source code to use the product.
Depending on configuration and use, Allure TestOps may process user account data and customer-submitted test data, including test cases and statuses, timestamps, error logs, screenshots and other artifacts, environment metadata, parameters, labels, and historical trends. Because logs, parameters, and artifacts may contain confidential or personal data, customers should avoid submitting secrets, production credentials, or unnecessary personal data and should configure tests and integrations accordingly.
For information about how Qameta processes personal data, please see our Privacy Policy.
Allure TestOps Cloud
Allure TestOps Cloud is a SaaS service operated by Qameta and hosted on AWS infrastructure. Qameta manages the Cloud environment, application deployments and upgrades, monitoring, backups, and platform operations.
External connections to the Cloud service are protected using TLS. Cloudflare provides edge and DDoS protection, as well as authoritative DNS services. Qameta maintains centralized logging and monitoring, disaster recovery backups, and incident response procedures for the Cloud service.
More information is available from AWS Security, the Cloudflare Trust Hub, and the Allure TestOps Cloud documentation.
Allure TestOps On-premise
Allure TestOps on-premise is a self-hosted deployment operated in the customer's environment. Customers are responsible for securing and maintaining their infrastructure and network, configuring identity and access controls, maintaining backups and monitoring, and keeping their Allure TestOps deployment up to date.
Qameta provides security fixes only in the latest generally available release of Allure TestOps. Security fixes are not backported to earlier releases. To receive security fixes, Server customers must upgrade to the latest release and follow the supported upgrade paths described in the release notes.
Applicable support and update terms are described in the Software License Terms.
Allure TestOps Plugins and Tools
Qameta provides proprietary plugins and tools that extend Allure TestOps integrations with CI/CD platforms, IDEs, issue trackers, and related development workflows. These components are provided for use with Allure TestOps or other Qameta products and are distributed under the applicable Qameta End User License Agreement. Customers should configure integrations using least-privilege permissions, protect credentials and tokens used by the integrations, and keep deployed components up to date.
Allure Report and Open-Source Ecosystem
Qameta develops and supports Allure Report as part of the broader Allure ecosystem, together with the open-source community. Allure Report is an open-source, framework-agnostic test reporting tool licensed under Apache 2.0, with integrations for 50+ testing tools and frameworks. Allure Report runs locally and does not require test data to be sent to Qameta or any hosted service. Users are responsible for securing generated reports and the locations where they are stored or shared. Most components of the Allure ecosystem are open source and can be used independently or with Allure TestOps.
Product Security and Access Controls
Qameta integrates security into its software development lifecycle. Changes are peer-reviewed, and automated security checks are used to identify known vulnerabilities in dependencies and exposed secrets. Security findings are assessed and remediated based on risk.
Access to Qameta-managed production environments is restricted to authorized personnel based on least privilege and is monitored. Allure TestOps provides roles, groups, and configurable permission sets. Server deployments support LDAP, OpenID Connect, SAML 2.0, and configurable audit logging.
Sensitive values stored in the Allure TestOps database, such as integration credentials, are encrypted using AES-256. Server customers are responsible for securely configuring and protecting the encryption key as described in the product documentation.
Payments
Payment card data is processed by Stripe and QuickBooks Payments. Qameta does not store full payment card details. Stripe is a PCI Level 1 service provider.
Security and Compliance
Qameta maintains an information security program designed to protect customer data and systems. Qameta has completed a SOC 2 Type II examination covering the Security category of the AICPA Trust Services Criteria.
Security and compliance materials, including the SOC 2 report, are available through the Trust Portal, subject to access requirements.
Report a Security Issue
To report a suspected security vulnerability or other security issue affecting Qameta products or services, contact security@qameta.io.
Please include the affected product or service, a description of the issue, reproduction steps where available, and relevant supporting information.
Qameta Software Inc. does not operate a public bug bounty program and does not offer monetary rewards for vulnerability reports.