Security

What we touch, what we keep, and what we never send anywhere

Adoptest is a comparison tool. It needs to read two documents and remember which versions it compared. That is the whole footprint.

Where it runs

The app runs inside your documentation platform's own app infrastructure. We do not operate external application servers that receive your page content.

Content stays inside the platform

Page content is read, compared and discarded within a single invocation. It is not written to a database, not queued, and not logged. When a check finishes, the text is gone.

The app makes no external network calls during a normal check. If you switch on link checking, it contacts only the sites linked from the page to test whether those links still work.

What we store

  • Account identifiers provided by your platform (workspace id, user id, display name)
  • Mapping records: which page is linked to which source artifact
  • Version identifiers and content hashes used to detect change
  • Findings you have already been shown, so we do not repeat them
  • Approval records: who approved, when, page version, source version
  • Operational counters used for plan limits

Permissions requested, and why

  • Read pages and spaces. This fetches the page and source being compared.
  • Add comments. This delivers a finding where the owner will see it.
  • Add attachments. This attaches a report export when you ask for one.

Adoptest never edits page content. Suggested edits are shown to you and pasted by a human. There is no write path into the body of a page.

Data residency

Storage follows your own instance's region. We do not relocate or replicate metadata to a different region.

AI use

A model reads prose into structured steps inside the host platform. It does not decide whether two things agree. Deterministic code makes that judgment, and recorded readings are reused so an unchanged check is reproducible. Every model-contributed finding is labelled, and a model can add a finding but never remove one.

Reporting a vulnerability

Email connect@adoptest.com with a description, affected surface and reproduction steps. We acknowledge within two business days and give you a triage outcome within ten business days. Please do not test against another customer's data, and give us a reasonable window before public disclosure. We will credit you if you would like that.

General security contact

Use connect@adoptest.com for security matters and all other enquiries.