Security
How runs, accounts and data are protected.
Isolated runs
Every run gets two new servers, one for your app and one for the load, on a private network of their own with their own firewalls. Nothing is shared between customers. Your app is not reachable from the internet during the test.
Both servers are deleted when the run ends, fails or is stopped. If a run gets stuck, its servers are deleted automatically when its time limit passes.
Your app during a test
Your app can reach the internet so it can download what it needs at startup. Outbound traffic is restricted and rate limited to prevent abuse.
Load is only ever sent to your app, over the private network. A run cannot be pointed at any other address.
Use test credentials and test data. Do not give a run production secrets or point it at a production database.
Run secrets
Environment variable values, request headers and request bodies are encrypted before they are stored, used only to start the run, and deleted shortly after the run ends. They never appear in reports or logs. Variable names are kept so the report can list them.
Accounts
Passwords are stored as salted hashes, never in plain text. Sessions use secure, HttpOnly cookies. Resetting your password signs out every session. Sign-in and password reset attempts are rate limited.
GitHub access
Public repositories need no connection. For a private repository you install the Stresix GitHub App on the repositories you choose. It has read-only access to their contents and metadata, and it cannot push, open issues or change settings.
You can disconnect GitHub from Settings and uninstall the app from GitHub at any time.
Repositories you submit
Submitted repositories are treated as untrusted. Their size is limited, and builds run in isolated containers with fixed CPU and memory limits.
Your data
You can download all of your data or delete your account from Settings. The Privacy Policy describes what is stored and who processes it.
Reporting a vulnerability
Email [email protected] with "security" in the subject. Good-faith research is welcome. Do not access other people's accounts or data, and do not degrade the service for others. Reports get a reply, and public credit if you want it.
Certifications
Stresix has no SOC 2 or ISO 27001 certification, has not had a formal penetration test, and offers no uptime guarantee.