EU data centers by default
Cloud deployments store data in European data centers. Custom regions are available worldwide on request, and full on-prem deployment is available for maximum control.
Wopee.io security means your test data stays in EU data centers by default, is encrypted in transit and at rest, is never used to train AI models, and is deleted within 30 days when you leave. This page explains what connects where, from the Commander control plane to the testing agents, and which deployment options keep your application behind your firewall.
The six answers every security review asks for first
Cloud deployments store data in European data centers. Custom regions are available worldwide on request, and full on-prem deployment is available for maximum control.
We never train models on your code or test data. Everything you share is used exclusively to deliver the agreed testing services.
When an engagement ends, all exchanged data is deleted from Wopee.io systems within 30 days, unless otherwise agreed in writing.
Secure cloud infrastructure with encryption at rest and in transit, built on a secure development lifecycle with code reviews and vulnerability scanning.
Configurable roles with appropriate permission levels and the principle of least privilege. Access management can be administered by Wopee.io or delegated to your team.
A Data Processing Agreement is available now. Formal certifications (SOC 2, ISO 27001) are on our roadmap. Meanwhile we maintain rigorous internal security practices.
The exact question security teams ask before hosting or allowlisting anything. Here is the full data flow.
| Component | Where it runs | What it connects to & why | Data involved |
|---|---|---|---|
| Wopee.io Commander (control plane) | Wopee.io cloud (EU data centers by default) | Your browser over HTTPS, so your team can review tests, results, and baselines | Test definitions, run results, screenshots, traces, reports |
| AI Testing Agents (execution) | Wopee.io-managed runners by default; self-hosted runners inside your network on Enterprise | Your application under test: only the environments and URLs you configure | Pages of the app under test, screenshots, execution logs |
| Test artifacts | Git repository with full commit history | Commander for review and editing; test cases can be published to your own repo | User stories, test cases, generated Playwright code |
| LLM provider | Wopee.io-managed by default; your own Azure OpenAI, Google Vertex AI, Anthropic, or OpenAI-compatible endpoint on Enterprise | Agents call it at runtime; provider credentials are stored encrypted | Prompts built from your app context, never used for model training |
Agent runs are dispatched as CI jobs with a dedicated repository per project, and execution logs stay fetchable for full traceability. Exact network requirements (IP ranges and egress endpoints for your region) are provided during your security review.
Four deployment options, from managed cloud to fully inside your network
Agents run from the Wopee.io cloud and reach your application over the internet. Data stays in EU data centers. The fastest way to start.
Your application stays behind your firewall. You allow Wopee.io cloud IP ranges, provided during onboarding.
A secure VPN or SSH tunnel between the Wopee.io cloud and your internal network. Nothing else is exposed.
Agents execute inside your network and your application is never reachable from outside. Full on-prem deployment of the platform is available for maximum data control.
Where your data lives, how it is separated, and when it is deleted
Autonomous does not mean unsupervised. Every AI output is transparent, traceable, and under your control.
All AI-generated outputs (test cases, reports, analyses) can be reviewed before use.
Modify, refine, or customize any generated content.
Regenerate outputs with adjusted parameters or additional context.
Reject any output that does not meet your quality standards.
Guardrails run at every stage: validation checks in agent design, input/output verification on tools, automated quality checks on generated outputs, and anomaly detection that flags unexpected patterns for review.
User actions are logged in an audit trail, and system activity is continuously monitored.
Formal certifications (SOC 2, ISO 27001) are on our roadmap. Meanwhile we maintain rigorous internal security practices. A Data Processing Agreement is available today.
Encryption, role-based access, audit logging, and a secure development lifecycle are already in place. We answer security questionnaires directly. Bring yours.