Security

Last updated: April 21, 2026

This page describes the security controls that are actually in place today. We don't list controls we plan to build or certifications we're pursuing as if they already apply. If something isn't here, it isn't in production yet — see Compliance Roadmap for what's coming.

1. Session and Authentication

2. Role-Based Access Control

Three roles are enforced at the API layer:

Every API endpoint that creates, modifies, or triggers runs is gated by the platform_admin role — operator work is never exposed to tenant users even by accident.

3. Salesforce Authentication

4. Data at Rest and in Transit

5. Verification Artifacts

Test runs produce screenshots, HTML reports, and browser video recordings. Because these are captures of a live Salesforce session, they may incidentally contain business data visible on screen at the time. We treat them as sensitive:

6. Uploads and Input Validation

7. Content Security Policy

Our web surface ships a strict Content Security Policy. script-src is restricted to 'self' plus the Cal.com embed domain — we do not permit 'unsafe-inline' for scripts. Combined with the HttpOnly session cookie, this means even a successful XSS payload cannot execute arbitrary JavaScript or read the session. (We still permit inline style attributes in our marketing HTML; tightening style-src is on our roadmap.)

8. Logging, Monitoring, and Incident Detection

9. Subprocessors

We use the following service providers to operate Release Assurance. Each one is bound by its own terms of service and data-processing commitments.

10. Incident Response and Vulnerability Disclosure

If you believe you've found a security vulnerability, email security@ReleaseAssurance.com. We aim to acknowledge within one business day and provide an initial triage within three.

If a security incident affects your data, we will notify affected tenants within 72 hours of confirmed impact. We do not currently operate a public bug bounty program; this may change as the platform matures — see the roadmap below.

11. Data Processing Agreement

A Data Processing Agreement (DPA) aligned with GDPR Article 28 is available on request. Email dpa@ReleaseAssurance.com and we will return a signed copy within one week.

12. Compliance Roadmap

We are pre-launch. No third-party compliance certifications apply today. What we are actively working toward:

Questions? See our Privacy Policy and Terms of Service, or contact security@ReleaseAssurance.com.