Deployment & data handling

Your projects stay in your workspace.

Qoretix handles repositories, test accounts, requirements documents, and execution evidence per project. Project settings and roles determine what is read, what is retained, and who can access it.

Data we handle

What we read. What we retain.

Connect only what testing requires. Retain only what supports the decision.

Workspaces isolated by organization Available now

Customers see only their organization's projects and results. Other organizations' repositories, cases, and execution history do not appear in their lists. Three roles govern access: QA lead (settings, approval, release sign-off), tester (authoring, execution, review), and customer (viewing results, release decisions).

Repository access scope Available now

GitHub repositories connect through a GitHub App, with access limited to repositories you authorize. Code is read for case generation, PR-based test suggestions, and supply chain scans. Code scanning, secret scanning, and dependency alerts are read-only; disabled scans show as unknown, not zero findings.

Test accounts and target URLs Available now

Target URLs and login details are registered in project settings and used only for screen collection and UI/API test execution. We recommend staging environments. You decide whether to test production.

Requirements documents Available now

Attach feature lists, requirements, wireframes, WBS documents, and permission matrices as DOCX, XLSX, PPTX, PDF, images, or Markdown. Documents are used only for test planning, case generation, and requirements coverage calculations.

Execution evidence retention Available now

Every run produces an HTML report, execution logs, and screenshots and replay videos for failed cases. Supply chain scans record the dependency tree at the tested commit. Execution history is retained as evidence, for the period agreed in your contract.

Deployment and data handling terms

We agree on deployment, data location and retention, and access scope during consultation, based on your security requirements. We start with a mutual NDA and record the agreed terms in a written services agreement.

Implementation consultation

Frequently asked questions

Deployment and data: your questions answered.

Does Qoretix modify code when I connect a repository?
No. Repositories are connected for reading and used for case generation, PR-based test suggestions, and supply chain scans. A person approves or rejects test suggestions in the workspace.
Can I test a production environment?
We recommend staging. UI tests open real screens and enter values, which can affect production data. If production testing is necessary, we agree on test accounts and scope during consultation.
Who can see test account login details?
Only QA leads with project configuration permissions can register or change them. For managed QA, IXC experts access projects only within the roles you grant.
How long is execution evidence retained?
Screenshots, replay videos, logs, and HTML reports are retained with execution history as evidence for release decisions. Retention periods and deletion procedures are agreed in the contract. Evidence can be organized by project at your request.
What materials can you provide for our security review?
After an implementation consultation and mutual NDA, we provide documentation on access scope, data flows, and retention terms. We can also respond to your security questionnaire.
Can Qoretix receive data from our existing security scanners or observability tools?
Currently, release decisions use security alerts from connected GitHub repositories and public vulnerability database results. Integrations with external scanners and observability tools are in preview. You choose which data to share and its scope.

Start with your security requirements.

Request a consultation to discuss deployment, access scope, and retention terms. Use the same contact channel as demo requests.

sales@qoretix.com+82-33-242-0210Weekdays, 10:00–18:00 KST