Security & Compliance

Paste a prompt and expected behavior; get an eval checklist and version regression guard. For dev and QA teams shipping LLM-powered product features.

What we handle

TestPilot processes the text or configuration you submit to produce its output. We do not train public models on your submissions without explicit consent.

Data handling commitments

  • Inputs are used only to produce your result; not published or indexed by us.
  • Payments processed by Waffo Pancake (merchant of record) — we do not store card data.
  • Exports contain only your own run data.
  • EU AI Act mapping — high-risk actions are logged and mapped to obligation articles where applicable. ref: EU AI Act

Compliance posture

  • GDPR-aligned practices (lawful basis, data minimization, access on request). ref: GDPR
  • OWASP guidance for web app and LLM prompt-injection hygiene. ref: OWASP
  • We do NOT claim certification (no SOC 2 / ISO 27001 badge unless earned).

⚠️ We do NOT guarantee

  • We do NOT guarantee compliance with any regulation.
  • We do NOT claim 100% security or uptime.
  • We do NOT promise the tool will "never miss" an issue — coverage is fixed at the named checks.