Trust & Safety

Security at TestPilot

Last updated: May 27, 2026

Security is foundational to everything we build. Here's how we protect your data, your assessments, and your candidates.

Encryption

  • TLS 1.2+ for all data in transit
  • AES-256 encryption for data at rest
  • Encrypted database backups
  • Secure key management with rotation policies

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication support
  • Session timeout and single active session enforcement
  • Principle of least privilege for all internal systems

Infrastructure

  • Hosted on enterprise-grade cloud infrastructure
  • Isolated environments per customer (logical separation)
  • Automated daily backups with point-in-time recovery
  • DDoS protection and rate limiting

Exam Integrity

  • Secure browser mode with full-screen lockdown
  • Tab-switch and focus-loss detection
  • Copy/paste and DevTools blocking
  • Auto-submit on critical violation threshold

Monitoring & Auditing

  • Real-time anomaly detection and alerting
  • Comprehensive audit logs for all admin actions
  • Uptime monitoring with automated incident response
  • Regular penetration testing and vulnerability scans

Organisational Security

  • Security awareness training for all staff
  • Background checks for employees with data access
  • Documented incident response and breach notification procedures
  • Vendor risk assessments for all sub-processors

Responsible Disclosure

If you discover a security vulnerability in TestPilot, we ask that you report it responsibly. We commit to acknowledging your report within 48 hours and working with you to resolve the issue promptly.

Report a Vulnerability

support.testpilot@gmail.com