Specmonkey

Security

Security Policy

  1. Introduction

Protecting customer data is one of our most important responsibilities. We’re committed to being transparent about our security practices and helping you understand our approach. Highlights of our security program are provided below.

  1. Information We Collect

  • Additional Standards: We align our practices with the principles of GDPR, CCPA, HIPAA, and ISO 27001 to meet global security and privacy expectations, aiming to provide enterprise-grade protection for all users.
  1. Data Protection

  • Encryption: All data is encrypted in transit (using TLS 1.3) and at rest (using AES-256 encryption) on Microsoft Azure servers. This includes user data (e.g., name, email), project data (e.g., test cases, task descriptions), and usage logs.
  • Secure Storage: Data is hosted on Azure, leveraging its enterprise-grade infrastructure and strict security protocols.
  • Backup Security: Test case backups in Azure DevOps are encrypted and access-controlled to prevent unauthorized access.
  1. Access Controls

  • Role-Based Access: Users are assigned roles (e.g., QA engineer, manager, admin) within Azure DevOps, ensuring they only access data relevant to their responsibilities (e.g., admins manage settings, engineers edit test cases).
  • Authentication: Multi-factor authentication (MFA) is enforced for all Specmonkey accounts to prevent unauthorized access.
  1. AI and Data Security

  • AI Model Protection: Specmonkey’s AI models (used for test case generation) are trained on anonymized, aggregated data to prevent exposure of personal or project-specific information.
  • Input Sanitization: Task descriptions and user inputs are sanitized to prevent injection attacks or malicious code execution.
    Model Isolation: AI processes run in isolated environments to ensure no cross-contamination of data between users or teams.
  1. Third-Party Integrations

  •  As a native Azure DevOps extension, Specmonkey leverages Azure’s security framework, including encrypted data transfers and role-based access controls.
  1. Employee Training and Access

  • Security Training: All Specmonkey employees undergo regular security awareness training, covering phishing prevention, data handling, and secure coding practices.
  • Access Restrictions: Employees have access to user data only on a need-to-know basis, with strict logging and monitoring of all access events.
  • Background Checks: Employees handling sensitive data undergo background checks during hiring.
  1. Vulnerability Management

  • Regular Testing: We conduct quarterly penetration testing and vulnerability assessments to identify and address potential weaknesses.
  • Patching: Software updates and security patches are applied promptly to mitigate known vulnerabilities.
  1. User Responsibilities

  • Secure Practices: Users must maintain account security (e.g., using strong passwords, enabling MFA) and report suspicious activity promptly.
  • Data Input: Ensure that data uploaded to Specmonkey (e.g., task descriptions) does not contain sensitive personal information beyond what is necessary for QA purposes.
  1. Changes to This Policy

Specmonkey may update this Security Policy to reflect changes in our practices, technology, or legal requirements. Significant updates will be communicated via email or in-app notifications.

  1. Contact Information

For inquiries or data requests, please contact us at:

Scroll to Top