Security
How DontBreak handles your site and your data
DontBreak opens your site in a real browser and keeps what it saw. This page explains where that happens, what we store and encrypt, how long we keep it, and how to reach us about a security problem.
Hosting
AWS, us-east-1
Application servers, database, test browsers, file storage and email run on AWS in N. Virginia, USA.
Test runs
A fresh container per run
Each run gets its own short-lived container on AWS Fargate, stopped once its results are uploaded.
Stored secrets
Encrypted field by field
Site passwords, custom header values, integration tokens and variable values are encrypted in the database.
Payments
Handled by Stripe
Stripe takes the payment as merchant of record. Card details never reach our servers.
Sent with Amazon SES
Alerts and account email go out through Amazon SES from the dontbreak.io domain.
Run history
14, 30 or 90 days
Runs are kept for your plan's history window, and run artifacts are deleted after 90 days at most.
Where DontBreak runs
DontBreak is run by Audiencely UAB, a company registered in Vilnius, Lithuania. The application servers, database, test browsers, file storage and email all run on Amazon Web Services in us-east-1 (N. Virginia, USA). Data transferred there from the EU is covered by the European Commission's Standard Contractual Clauses.
A few other providers handle specific jobs, such as AI features, error monitoring, analytics and live progress updates. The full list, what each one receives and where it processes data is in sections 6 and 8 of our Privacy Policy.
How a test run is isolated
- One container per run. Every run gets its own short-lived container on AWS Fargate. A container is claimed by a single run, so two runs (and two sets of credentials) never share one, and it is stopped once that run's screenshots and video are uploaded.
- It visits your site like any visitor. The browser reaches your site over the public internet. DontBreak never connects to your servers or your database.
- Server-side fetches are fenced. Our AI site crawler and the screenshot uploads for Trello, Jira and GitHub refuse private, internal and cloud-metadata network addresses.
Running a site that sees our traffic? The docs page on DontBreak's test traffic explains what it looks like, how to let it through your firewall, and how to report traffic you didn't ask for.
What we encrypt, and what that means
- Field-level encryption for the most sensitive values you store: basic-auth passwords, custom request-header values, access tokens for the integrations you connect (Slack, Jira, Trello, GitHub), and the values of your custom variables. These sit in encrypted database columns, and stored passwords and tokens are also left out when your account data is sent to the browser.
- Account passwords are stored only as bcrypt hashes. Two-factor authentication is available, and its secrets and recovery codes are stored encrypted.
- HTTPS everywhere. The session cookie is HTTPS-only, HttpOnly and SameSite=Lax, and login and two-factor attempts are rate limited.
Two things to know. First, encryption covers the fields listed above, not every piece of data: test steps, URLs and run reports are not encrypted field by field. Second, a stored password has to be decrypted to be typed into your site, so it shows up in that run's step details. Use dedicated test accounts and non-production secrets wherever you can.
Screenshots, videos and how long we keep them
Run screenshots, videos, console logs and step details are captures of the page being tested. They contain whatever that page showed, including your users' personal data if you test a live, logged-in site. Test with test accounts and test data where you can.
- While your plan is active, runs and their artifacts are kept for your plan's run history: 14 days on Solo, 30 on Team, 90 on Agency.
- If your subscription ends, your plan's window still applies for 30 days, then it drops to 7 days.
- Our storage lifecycle deletes run artifacts after 90 days at most.
- Temporary test inboxes, used to test signup and password-reset emails, are deleted after 4 hours by default unless you pin them.
- Application logs are kept for 30 days and error reports for up to 90 days.
AI features
AI features, such as failure analysis and step descriptions, send screenshots and page content of the tested page to Anthropic's Claude API. AI Check steps send a text description of the page to typesafe.ai instead: no screenshots, and password, payment-card and one-time-code fields are removed first. We don't have a zero-retention arrangement with Anthropic. If a page is too sensitive for that, don't use AI features on it.
Payments and access
- Payments. Stripe sells subscriptions and run packs as merchant of record. We keep your billing profile and Stripe references, never your card number or CVC.
- Teams. Data is scoped to the team it belongs to, and everyone on a team can see that team's tests and reports.
- Our staff. A small number of DontBreak staff accounts can access customer data to run and support the service, and only for that.
What we don't claim
DontBreak doesn't hold SOC 2 or ISO 27001 certification, and your data is hosted in the US, not in the EU. If you process your own users' personal data with DontBreak, we'll sign a Data Processing Agreement: email support@dontbreak.io.
Report a vulnerability
Email security@dontbreak.io with what you found, the URL or feature involved, the steps to reproduce it, and what an attacker could do with it. Please give us a reasonable time to fix it before you share it publicly.
While testing, use only accounts you own, don't access or change other customers' data, and don't run scans that slow the service down for everyone. We don't run a paid bug bounty. Our security.txt lists the same contact.
Report abuse or unwanted test traffic
If DontBreak runs are hitting a site you own and you didn't ask for them, or you think someone is misusing DontBreak, email abuse@dontbreak.io. Include the URL that was visited and the date and time (with time zone), and the IP address if you have it. Our test traffic page explains what our traffic looks like.
More
- Service status
- Privacy Policy, the legal version of everything above
- Questions: support@dontbreak.io
Last updated 7 October 2026.
Your next deploy could be the calm one.
Put your first flow on watch in five minutes — free for 14 days, no commitment, cancel anytime.
