Trust

Your app, your secrets, your tests. Here's exactly where they go.

The engine is open source, so most of what this page says can be checked in the code; the docs give the file names.

  • Replays use no AI
  • Secrets never reach a model
  • One pinned AI provider, zero data retention

Which AI sees your app

  • Replays: none. After a test is written, running it uses no AI. A replay of an unchanged app contacts only the site under test.
  • Our hosted AI. When you use our AI to write or fix a test, the request goes through OpenRouter to DeepSeek-V4.1-Flash, run by DeepInfra (United States, fp8). We pin that provider, require zero data retention, and allow no fallback to any other provider or model. A request has the step text, a text description of the page and sometimes a screenshot.
  • Your own key. The request goes straight from the test runner to your provider, under your account and their terms. It doesn't pass through us.
  • Never sent to any AI: secret values, your API keys, your test files as a whole, other tests' pages. Use test data: if a page shows a real person's name, that text can be in the page description.

Secrets

A secret value is typed by the test runner into pages on its own allowed domains only. It is registered with a redactor that scrubs every log line, result and artifact, the browser masks the field and pauses the trace while typing, and the AI sees only the secret's name. Stored secret values are encrypted; the app can set or clear them but never read them back.

One known limit: a secret embedded inside a larger encoded value (for example base64 of user:password) isn't detected unless the code that builds it registers it. Known limits.

The agent's safety

The agent can only reach the domains you allow, enforced below the browser. It has a closed set of actions and no shell or file access, and treats page content as untrusted. Production environments block destructive actions unless a test declares them. The safety model.

What we store, and for how long

  • Your tests and recordings stay until you delete them. Connect GitHub and the repository stays the source of truth.
  • Run results and evidence (screenshots, video, traces, logs; scrubbed of secrets) are kept for your plan's retention: Free 7 days, Cloud (your own key) 14 days, Solo Dev 14 days, Pro Dev 30 days, Team 90 days. A daily job then deletes them.
  • Account and billing records are kept while your account exists, and as long as the law requires for invoices.
  • Deletion: delete a project or your account in the app, or email privacy@optestra.com and we'll delete your data on request.

Where

The app, API and test workers run on Google Cloud in the United States (us-east4, Virginia). Customer data is processed in the United States by the subprocessors listed here (9 today). There is no regional choice at launch; EU data residency is on the roadmap, not promised.

This website

No cookies, no analytics, no third-party scripts, no fonts or images loaded from anywhere else. The web app sets one session cookie to keep you signed in and protect your changes from other sites; no trackers and no advertising.

Report a problem

Found a vulnerability? Email security@optestra.com. We read every report, and won't pursue anyone who tests in good faith and tells us.

Details for every claim: what data goes where in the docs.