Contents01Where is AlloyQA hosted and processed?02Which AI provider does AlloyQA use?03What customer data does AlloyQA access?04Does AlloyQA scan the entire backlog or repository?05Is customer data used to train AI models?06What information is stored?07How long is information retained?08Who can access customer information?09What does Implementation Check access?10When can AlloyQA write back to connected tools?11How can customers delete their information?12What analytics and operational logs are collected?13Which third-party subprocessors are used?14What deployment options are available?15How can a security team contact AlloyQA?
Trust

Security &
Data Handling

AlloyQAUpdated July 15, 202615 sections

How AlloyQA processes customer content, uses AI infrastructure, limits connected-system access, stores review data, and supports deletion.

Security at a glance
Limited ticket access

Reviews use tickets selected by a user or matched by a configured Jira or Linear workflow trigger.

Vertex AI processing

AlloyQA sends relevant review context to Google Cloud Vertex AI for AI-assisted analysis and generation.

No model training

AlloyQA does not use customer content to train its own models or shared foundation models.

Approved write-back

Ticket rewrites require an authenticated user action and a finalized ticket update before Jira or Linear is changed.

Deletion controls

Users can delete saved reviews; workspace admins can delete a team space through the product.

Encrypted integrations

Integration credentials are encrypted before storage and used only to operate connected services.

01

Where is AlloyQA hosted and processed?

AlloyQA is hosted on Netlify. Account authentication and application data use Supabase, and AI requests are processed through Google Cloud Vertex AI.

02

Which AI provider does AlloyQA use?

AlloyQA's production AI integration is Google Cloud Vertex AI. Relevant ticket, review, QA, and implementation context is sent to Vertex AI when an AI-assisted feature runs.

Only the context needed to provide the requested AI-assisted functionality is submitted for processing.

03

What customer data does AlloyQA access?

Depending on the feature and connected tools, AlloyQA can process account identifiers; ticket titles, descriptions, acceptance criteria, comments, workflow status, linked context, and project metadata; generated findings, decisions, suggested updates, and QA coverage; and integration configuration.

For implementation-related features, AlloyQA can also process repository and pull-request or merge-request identifiers, metadata, changed files, diffs, test-change signals, implementation-check results, and uploaded test evidence.

04

Does AlloyQA scan the entire backlog or repository?

Ticket reviews are initiated for a ticket a user selects or for an issue matched by a configured Jira or Linear status workflow. AlloyQA does not crawl the entire backlog by default.

Implementation Check works on the pull request or merge request associated with a review. It reads the metadata and changes needed for that check rather than scanning the entire repository by default.

Connected integrations request the permissions needed to read relevant work items and perform customer-enabled actions. Customers can review and revoke those permissions through the connected provider.

05

Is customer data used to train AI models?

No. AlloyQA does not use customer content to train its own models or shared foundation models. Customer content is sent to Google Cloud Vertex AI only to provide the requested product functionality.

This statement describes AlloyQA's current product use of customer content; it is not a claim that AlloyQA operates a separately trained proprietary model.

06

What information is stored?

Supabase stores authentication and application records needed to operate the service. Depending on the features used, these records can include profiles and workspace membership, integration configuration, tickets and saved reviews, decisions and team memory, findings and QA coverage, workflow and implementation-check records, uploaded evidence, comments, usage records, and billing references.

Integration credentials are encrypted before storage and are used only to operate the connected integration.

07

How long is information retained?

AlloyQA is currently formalizing a standard retention schedule. Until then, saved workspace information remains available until it is deleted by the customer or through a verified deletion request.

Some short-lived access links and invitations expire automatically to prevent later use.

08

Who can access customer information?

Access to customer information is limited to authorized personnel who require it to operate and support the service. Product access is protected through authentication, workspace membership checks and administrator permissions.

09

What does Implementation Check access?

When GitHub or GitLab is connected and Implementation Check is used, AlloyQA reads the relevant pull-request or merge-request metadata, changed files, diffs, repository identifiers, linked ticket reference, and test-change signals. It compares those changes with the finalized ticket and QA coverage.

Results and supporting metadata can be stored in Supabase, and a check comment can be posted to the relevant pull request or merge request when that workflow is configured.

10

When can AlloyQA write back to connected tools?

Ticket changes are synced only after an authenticated user reviews and finalizes the content in AlloyQA.

Separately, configured workflow automation can post review links or summaries to Jira or Linear, and configured GitHub or GitLab workflows can post or update implementation-check comments. Those comments are automated actions enabled by the connected workflow; they are distinct from rewriting ticket fields.

11

How can customers delete their information?

Users can delete individual saved reviews from review history, and workspace administrators can delete a team space through the product.

Disconnecting an integration removes its stored credentials from AlloyQA. Customers should also revoke the connection through the connected provider.

Full account deletion is currently handled through a verified request to security@alloyqa.com.

12

What analytics and operational logs are collected?

AlloyQA uses PostHog for limited page-view and product-action analytics. Session recording and automatic interaction capture are disabled.

AlloyQA collects limited operational logs needed to maintain reliability, diagnose errors and protect the service. Customer ticket content is not used for product analytics.

13

Which third-party subprocessors are used?

AlloyQA uses the following core service providers:

  • Netlify — web application and serverless-function hosting.
  • Supabase — authentication and application data storage.
  • Google Cloud Vertex AI — AI processing and generation.
  • PostHog — limited product analytics.
  • Resend — transactional and product email.

At a customer's direction, AlloyQA also exchanges data with connected Atlassian Jira and Confluence, Linear, GitHub, GitLab, and TestRail accounts when the relevant integration or workflow is used.

14

What deployment options are available?

AlloyQA is currently provided as a SaaS product. Private-cloud and on-premise deployment are not currently supported. AlloyQA does not currently offer a customer-selectable regional data-residency option.

15

How can a security team contact AlloyQA?

Security, privacy, data-handling, and deletion questions can be sent to security@alloyqa.com.

Assurance summary

Current security posture

Controls currently implemented

Authentication, workspace membership checks, administrator permissions, encrypted integration credentials, connected-workflow protections, and human-approved ticket write-back.

Documentation available

This Security & Data Handling page, the Privacy Policy, and the Terms of Service.

Privacy PolicyTerms of ServiceAlloyQA home
AlloyQA
Last updated: July 15, 2026