Security & NDA Compliance
Last Updated: March 15, 2026 • Standards governing all client interactions and testing environments
01Mutual Non-Disclosure Agreements (NDA)
We prioritize confidentiality from day one:
- Initial QA Assessments: Submitting an assessment request automatically binds our team to mutual confidentiality. We will never publicly disclose your application vulnerabilities, bug reports, or audit findings.
- Formal Engagements: Before receiving access to staging servers, private Git repositories, or API collections, we countersign your company's standard NDA or provide our comprehensive software testing NDA.
- Team Binding: Every engineer, SDET, and quality analyst at Ziara QA Labs operates under strict confidentiality contracts and intellectual property assignment agreements.
02Credential & Secret Management
Staging credentials and API keys are stored exclusively in end-to-end encrypted password vaults with mandatory multi-factor authentication (MFA). Secrets are never shared in unencrypted chat channels.
Upon completion of an audit or engagement, our team formally prompts you to revoke test credentials. Any cached staging tokens and VPN configurations are permanently removed within thirty days.
03Test Data Sanitization Requirements
To maintain regulatory compliance and eliminate data liability risks, we enforce the following data policy for all clients:
- No Real Financial Information: Clients must configure payment gateways in test/sandbox mode (e.g., Stripe test cards). Never supply real banking or credit card numbers.
- Sanitized Customer Records: User records in staging databases must be obfuscated or synthetic. Avoid seeding real end-user personally identifiable information (PII).
- Scoped Role Privileges: QA test accounts should be assigned only the minimal role-based permissions required to execute the agreed test scenarios.
04Secure Deliverable Handoff
Deliverables containing vulnerability analyses, console error traces, or architecture critiques are transferred through authenticated, encrypted channels:
- Automated test suites (Cypress, Playwright, Selenium) are delivered via direct Pull Request into your private Git repository or encrypted repository archive.
- Executive PDF audit reports and Loom walkthrough videos are password-protected or restricted strictly to client company email domains upon request.
05Reporting a Security Concern
If you believe you have discovered a potential security vulnerability related to any of our public tools or infrastructure, please contact us immediately:
Security Operations Team
Email: ziaratechqlabs@gmail.com
Subject Line: [SECURITY] Vulnerability Disclosure Report
We acknowledge security reports within 24 business hours.
