QAM Hub QAM Hub

Security at QAM Hub

Last reviewed: 15 September 2026

QAM Hub is a hosted test management system operated by QA Madness Sp. z o.o. Workspaces run on managed infrastructure in Western Europe, every request is authorised against the caller’s organization and project membership, and the team that builds and runs the product works inside the ISO/IEC 27001:2022 certified information security management system of QA Madness. This page sets out where your data is kept, who can reach it, what happens to it over time, how the AI features treat it, and how to report a vulnerability.

Certification and scope

QAM Hub is built and operated by QA Madness Sp. z o.o., which holds ISO/IEC 27001:2022 certification for the provision of software development and software quality assurance services. The same information security management system governs the team that builds and runs QAM Hub. The certificate is available on request.

That scope statement describes an organizational management system rather than a point-in-time examination of the application. What it covers is how the company works: risk assessment, access control and least privilege, personnel screening and confidentiality obligations, supplier and subprocessor management, change management, and incident handling. Those controls reach the engineers who deploy QAM Hub and the operators who hold production access, because they are the same people working under the same system.

Where your data lives

QAM Hub is a single multi-tenant deployment. Organizations share a database and are separated logically: every API request resolves the caller’s organization and project membership before a row is read or written, and no endpoint takes an organization identifier from the client.

ComponentProviderLocation
Application and APIRenderWestern Europe
Database (PostgreSQL)NeonWestern Europe
Attachments, screenshots, automation mediaCloudflare R2Western Europe
Web application deliveryVercelGlobal CDN
Edge protection: DDoS, WAF, DNSCloudflareGlobal

Hosting regions are set by us and are the same for every customer. QAM Hub does not offer per-customer region selection or a self-hosted deployment.

Encryption

In transit

The application is served over HTTPS only. Plain HTTP is redirected permanently, HSTS is set, and the apex domain redirects to the canonical www host. Traffic between your browser and QAM Hub, and between QAM Hub and every third-party service it calls, runs over TLS.

At rest

The database and the object storage bucket are encrypted at rest by their providers. On top of that, QAM Hub separately encrypts the values that would do the most damage if a database copy were ever read directly. These are sealed with AES-256-GCM under a key held outside the database, in the application environment:

Passwords are stored as bcrypt hashes with a work factor of 12 and are never recoverable: a forgotten password is replaced, never sent. Personal API tokens are stored as SHA-256 hashes and shown once, at creation, after which only the leading characters remain visible.

Files are not public. Uploads and downloads go through presigned URLs valid for 15 minutes, issued only after the request has been authorised against the project.

Access control in the product

Permissions sit at two levels. An organization role decides what someone can do to the workspace; a project role decides what they can do inside each project they belong to. A read-only organization role exists for stakeholders who should see results and change nothing. The full matrix is in Understanding roles and permissions.

ControlWhat it doesAvailability
Organization and project rolesAdministrator, member and read-only viewer at organization level; administrator, executor and viewer per project.All plans
Personal two-factor authenticationAuthenticator-app TOTP with trusted devices, switched on by each user.All plans
Enforced two-factor authenticationRequires every member of the organization to complete TOTP setup before using the workspace.Advanced
Google SSOSign-in restricted to the Google Workspace domains your administrators allow.Advanced
Organization audit logWho changed what and when, across every project in the organization.Advanced
Personal API tokensCreated and revoked by each user from their profile; they carry exactly that user’s permissions and are attributed to them in the audit trail.All plans

Sessions are bearer tokens with a seven-day lifetime. Signing out, changing a password and resetting two-factor authentication invalidate the token at once rather than waiting for it to expire. Sign-in, two-factor reset and organization lookup are rate limited per address and per IP, and repeated failures are written to the audit log.

Staff access. Platform administrators at QA Madness can reach organization content in order to operate the service, investigate a reported fault and act on support requests. Access is held by the people who need it to do that work, and administrative actions are recorded. Customer test data is not used for anything else.

Data retention and deletion

Automatic deletion applies to one category: the video recordings and Playwright traces attached to automated test runs. These are the bulk artefacts a CI pipeline produces by the gigabyte, and they are removed once they pass the retention period of your plan.

PlanAutomation video and trace retention
Standard30 days
Advanced60 days

Everything else stays until you delete it. Manual attachments, screenshots, library assets and knowledge documents are never removed automatically, and neither are test cases, runs, results or history.

When a trial ends or a subscription stops

Nothing is deleted. The workspace is blocked until a plan is paid for, and the content is there when it is. The same holds for a cancelled subscription. See What happens when your trial ends.

Getting your data out

An organization administrator can export the whole organization at any time as a ZIP archive of CSV files covering projects, suites, test cases, runs, results, requirements and checklists. The export stays available while a workspace is blocked, so nobody has to pay in order to leave.

Deleting an organization

Deletion is requested by the organization Owner from inside the application and is never automatic. The request records a verification contact, the Owner’s account address receives a receipt so that a request nobody authorised gets noticed, and a member of our team confirms it with the named contact before anything is removed. A request can be withdrawn until it is carried out.

AI and your data

The AI features run when someone triggers them. Nothing is sent to a model provider in the background, on a schedule, or while you browse.

FeatureWhat is sentProvider
Test case and checklist generation, bug analysis, quality analysisThe description you type, the project AI context and templates your administrators configured, the test cases under analysis, any enabled knowledge documents, and images you attach.OpenAI
In-app help assistantYour question, the product documentation, and the page you are on. Project content is not included.Google
Agent Flows (autonomous runs)The test cases in the flow, enabled knowledge documents, and screenshots captured from the site under test during the run.Anthropic

Calls are made server-side with keys held by the platform, so no provider credential and no model call passes through your browser. Content is sent for the duration of the request and is processed under the provider’s commercial API terms, under which inputs are not used to train their models.

AI features are included in every plan. If your organization would rather they were not available at all, write to us and we will switch them off for your workspace.

Backups and continuity

The database runs on a managed PostgreSQL service that takes automated backups and supports point-in-time recovery within a seven-day window. Files in object storage are held redundantly by the storage provider. Schema changes are applied at deploy time from version-controlled migrations, so a restored database matches the code running against it.

Availability is monitored from outside our own infrastructure and the result is public: the QAM Hub status page. The service sits behind Cloudflare for DDoS protection and traffic filtering.

Vulnerability reporting and testing

If you believe you have found a security issue in QAM Hub, write to [email protected]. Include the steps to reproduce it, the impact you believe it has, and whatever we need in order to see it ourselves. We acknowledge reports within one business day, tell you what we found, and let you know when it is fixed.

When you test, please work inside your own organization, do not reach or modify data belonging to anyone else, and do not run tests that degrade the service for other customers. Automated scanners and load generators trip our rate limiting and abuse controls and get the traffic blocked, so write to us first and we will agree a window and a target that make the results useful to both of us.

Privacy and legal

QA MADNESS Sp. z o.o., 151 Aleje Jerozolimskie, Office 10, Warsaw, Poland, is the controller for personal data processed through the service, and processing follows the GDPR. The Privacy Policy sets out what is collected, on what basis, how long it is kept and how to exercise your rights; the Terms of Use govern the service itself.

Service providers act as processors under written data processing agreements. They fall into the categories named in the Privacy Policy: hosting and database, object storage, content delivery and edge protection, transactional email, payment processing, and AI model providers. The current list of named providers is available on request. Where data is transferred outside the EEA it is transferred under standard contractual clauses, and a copy of those can be requested.

Card details do not reach QAM Hub. Subscriptions are handled by Stripe, which collects and holds the payment instrument; we store the subscription status, the plan and the seat count. See Billing, subscriptions and seat changes and Pricing.

Contact

Last reviewed 15 September 2026. This page is versioned with the product: it changes when the product changes, not on a schedule.