Reviews use tickets selected by a user or matched by a configured Jira or Linear workflow trigger.
Security &
Data Handling
How AlloyQA processes customer content, uses AI infrastructure, limits connected-system access, stores review data, and supports deletion.
AlloyQA sends relevant review context to Google Cloud Vertex AI for AI-assisted analysis and generation.
AlloyQA does not use customer content to train its own models or shared foundation models.
Ticket rewrites require an authenticated user action and a finalized ticket update before Jira or Linear is changed.
Users can delete saved reviews; workspace admins can delete a team space through the product.
Integration credentials are encrypted before storage and used only to operate connected services.
Where is AlloyQA hosted and processed?
AlloyQA is hosted on Netlify. Account authentication and application data use Supabase, and AI requests are processed through Google Cloud Vertex AI.
Which AI provider does AlloyQA use?
AlloyQA's production AI integration is Google Cloud Vertex AI. Relevant ticket, review, QA, and implementation context is sent to Vertex AI when an AI-assisted feature runs.
Only the context needed to provide the requested AI-assisted functionality is submitted for processing.
What customer data does AlloyQA access?
Depending on the feature and connected tools, AlloyQA can process account identifiers; ticket titles, descriptions, acceptance criteria, comments, workflow status, linked context, and project metadata; generated findings, decisions, suggested updates, and QA coverage; and integration configuration.
For implementation-related features, AlloyQA can also process repository and pull-request or merge-request identifiers, metadata, changed files, diffs, test-change signals, implementation-check results, and uploaded test evidence.
Does AlloyQA scan the entire backlog or repository?
Ticket reviews are initiated for a ticket a user selects or for an issue matched by a configured Jira or Linear status workflow. AlloyQA does not crawl the entire backlog by default.
Implementation Check works on the pull request or merge request associated with a review. It reads the metadata and changes needed for that check rather than scanning the entire repository by default.
Connected integrations request the permissions needed to read relevant work items and perform customer-enabled actions. Customers can review and revoke those permissions through the connected provider.
Is customer data used to train AI models?
No. AlloyQA does not use customer content to train its own models or shared foundation models. Customer content is sent to Google Cloud Vertex AI only to provide the requested product functionality.
This statement describes AlloyQA's current product use of customer content; it is not a claim that AlloyQA operates a separately trained proprietary model.
What information is stored?
Supabase stores authentication and application records needed to operate the service. Depending on the features used, these records can include profiles and workspace membership, integration configuration, tickets and saved reviews, decisions and team memory, findings and QA coverage, workflow and implementation-check records, uploaded evidence, comments, usage records, and billing references.
Integration credentials are encrypted before storage and are used only to operate the connected integration.
How long is information retained?
AlloyQA is currently formalizing a standard retention schedule. Until then, saved workspace information remains available until it is deleted by the customer or through a verified deletion request.
Some short-lived access links and invitations expire automatically to prevent later use.
Who can access customer information?
Access to customer information is limited to authorized personnel who require it to operate and support the service. Product access is protected through authentication, workspace membership checks and administrator permissions.
What does Implementation Check access?
When GitHub or GitLab is connected and Implementation Check is used, AlloyQA reads the relevant pull-request or merge-request metadata, changed files, diffs, repository identifiers, linked ticket reference, and test-change signals. It compares those changes with the finalized ticket and QA coverage.
Results and supporting metadata can be stored in Supabase, and a check comment can be posted to the relevant pull request or merge request when that workflow is configured.
When can AlloyQA write back to connected tools?
Ticket changes are synced only after an authenticated user reviews and finalizes the content in AlloyQA.
Separately, configured workflow automation can post review links or summaries to Jira or Linear, and configured GitHub or GitLab workflows can post or update implementation-check comments. Those comments are automated actions enabled by the connected workflow; they are distinct from rewriting ticket fields.
How can customers delete their information?
Users can delete individual saved reviews from review history, and workspace administrators can delete a team space through the product.
Disconnecting an integration removes its stored credentials from AlloyQA. Customers should also revoke the connection through the connected provider.
Full account deletion is currently handled through a verified request to security@alloyqa.com.
What analytics and operational logs are collected?
AlloyQA uses PostHog for limited page-view and product-action analytics. Session recording and automatic interaction capture are disabled.
AlloyQA collects limited operational logs needed to maintain reliability, diagnose errors and protect the service. Customer ticket content is not used for product analytics.
Which third-party subprocessors are used?
AlloyQA uses the following core service providers:
- Netlify — web application and serverless-function hosting.
- Supabase — authentication and application data storage.
- Google Cloud Vertex AI — AI processing and generation.
- PostHog — limited product analytics.
- Resend — transactional and product email.
At a customer's direction, AlloyQA also exchanges data with connected Atlassian Jira and Confluence, Linear, GitHub, GitLab, and TestRail accounts when the relevant integration or workflow is used.
What deployment options are available?
AlloyQA is currently provided as a SaaS product. Private-cloud and on-premise deployment are not currently supported. AlloyQA does not currently offer a customer-selectable regional data-residency option.
How can a security team contact AlloyQA?
Security, privacy, data-handling, and deletion questions can be sent to security@alloyqa.com.
Current security posture
Authentication, workspace membership checks, administrator permissions, encrypted integration credentials, connected-workflow protections, and human-approved ticket write-back.
This Security & Data Handling page, the Privacy Policy, and the Terms of Service.