Skip to main content
Trust & SecurityEU data residency by default

Security & data protection

Wopee.io security means your test data stays in EU data centers by default, is encrypted in transit and at rest, is never used to train AI models, and is deleted within 30 days when you leave. This page explains what connects where, from the Commander control plane to the testing agents, and which deployment options keep your application behind your firewall.

The short version

The six answers every security review asks for first

EU data centers by default

Cloud deployments store data in European data centers. Custom regions are available worldwide on request, and full on-prem deployment is available for maximum control.

Never used for model training

We never train models on your code or test data. Everything you share is used exclusively to deliver the agreed testing services.

Deleted within 30 days

When an engagement ends, all exchanged data is deleted from Wopee.io systems within 30 days, unless otherwise agreed in writing.

Encrypted in transit and at rest

Secure cloud infrastructure with encryption at rest and in transit, built on a secure development lifecycle with code reviews and vulnerability scanning.

Role-based access control

Configurable roles with appropriate permission levels and the principle of least privilege. Access management can be administered by Wopee.io or delegated to your team.

DPA available today

A Data Processing Agreement is available now. Formal certifications (SOC 2, ISO 27001) are on our roadmap. Meanwhile we maintain rigorous internal security practices.

What connects where, and why

The exact question security teams ask before hosting or allowlisting anything. Here is the full data flow.

Wopee.io Commander (control plane)

Where it runs
Wopee.io cloud (EU data centers by default)
What it connects to & why
Your browser over HTTPS, so your team can review tests, results, and baselines
Data involved
Test definitions, run results, screenshots, traces, reports

AI Testing Agents (execution)

Where it runs
Wopee.io-managed runners by default; self-hosted runners inside your network on Enterprise
What it connects to & why
Your application under test: only the environments and URLs you configure
Data involved
Pages of the app under test, screenshots, execution logs

Test artifacts

Where it runs
Git repository with full commit history
What it connects to & why
Commander for review and editing; test cases can be published to your own repo
Data involved
User stories, test cases, generated Playwright code

LLM provider

Where it runs
Wopee.io-managed by default; your own Azure OpenAI, Google Vertex AI, Anthropic, or OpenAI-compatible endpoint on Enterprise
What it connects to & why
Agents call it at runtime; provider credentials are stored encrypted
Data involved
Prompts built from your app context, never used for model training

Agent runs are dispatched as CI jobs with a dedicated repository per project, and execution logs stay fetchable for full traceability. Exact network requirements (IP ranges and egress endpoints for your region) are provided during your security review.

How testing reaches your application

Four deployment options, from managed cloud to fully inside your network

Default

Cloud (SaaS)

Agents run from the Wopee.io cloud and reach your application over the internet. Data stays in EU data centers. The fastest way to start.

Behind a firewall

IP allowlisting

Your application stays behind your firewall. You allow Wopee.io cloud IP ranges, provided during onboarding.

Enterprise

Secure tunnel

A secure VPN or SSH tunnel between the Wopee.io cloud and your internal network. Nothing else is exposed.

Enterprise

Self-hosted runner & on-prem

Agents execute inside your network and your application is never reachable from outside. Full on-prem deployment of the platform is available for maximum data control.

Residency, isolation & retention

Where your data lives, how it is separated, and when it is deleted

Residency

  • European data centers by default (cloud)
  • Custom region available worldwide on request
  • On-premises: fully within your own data centers

Isolation

  • Public cloud: Logical isolation via user permissions and access controls
  • Private cloud: Dedicated instance with full environment separation
  • On-premises: Complete isolation within customer-controlled infrastructure

Retention

  • All exchanged data deleted from Wopee.io systems within 30 days of an engagement ending, unless otherwise agreed in writing
  • Deletion timeline and process confirmed at exit

Human oversight, built in

Autonomous does not mean unsupervised. Every AI output is transparent, traceable, and under your control.

Review

All AI-generated outputs (test cases, reports, analyses) can be reviewed before use.

Edit

Modify, refine, or customize any generated content.

Regenerate

Regenerate outputs with adjusted parameters or additional context.

Reject

Reject any output that does not meet your quality standards.

Guardrails run at every stage: validation checks in agent design, input/output verification on tools, automated quality checks on generated outputs, and anomaly detection that flags unexpected patterns for review.

User actions are logged in an audit trail, and system activity is continuously monitored.

Certifications: where we stand

Formal certifications (SOC 2, ISO 27001) are on our roadmap. Meanwhile we maintain rigorous internal security practices. A Data Processing Agreement is available today.

Encryption, role-based access, audit logging, and a secure development lifecycle are already in place. We answer security questionnaires directly. Bring yours.

Need SSO, BYO-LLM, or on-prem?

See what the Enterprise deployment includes.