Data & Security

Last Updated: July 2026

This page describes, in plain language, how BesTest is built, where your data lives, what we store (and deliberately do not store), and how we protect it. It is written to answer the questions security and procurement teams usually ask. BT Studio is a small, focused team: we would rather be transparent about exactly what we do than hide behind vague claims.

1. Architecture: what runs where

BesTest consists of three parts:

  • The app, on Atlassian Forge. BesTest is built on Atlassian's Forge platform. The user interface runs inside your Jira Cloud experience, within Atlassian's security sandbox, and identity comes from your Atlassian account. We never see or handle your Atlassian password.
  • An API layer, on Cloudflare. Requests from the app go through our API gateway running on Cloudflare's infrastructure. It validates the caller's identity (a signed token derived from the Forge context) before any data is touched.
  • A dedicated database, on Supabase. Your test management data (requirements, test cases, test cycles, execution results) is stored in a PostgreSQL database hosted by Supabase in the region you select. Data is not stored inside your Jira issues, and we do not use Forge storage for customer content.

2. Where customer data is stored (and could be stored)

Customer data is stored in exactly one region, selected when your organization starts using BesTest:

  • European Union
  • United States
  • India

Data does not move between regions, and regional databases are fully separate from each other. Additional regions can be provisioned on request. The app code itself runs on Atlassian Forge and Cloudflare's global edge network; customer content is only persisted in the selected regional database. Our marketing website is hosted separately and stores no customer app data.

3. Data minimization: what we store, and what we refuse to store

We collect the bare minimum needed to run the product. Concretely, our database stores:

  • Your Atlassian site identifier (cloud ID) to know which Jira instance an organization belongs to
  • Pseudonymous Atlassian account identifiers (UUIDs) to attribute work items to users
  • The test management content your team creates: requirements, test cases, steps, cycles, executions, comments
  • References to Jira work items you link (issue IDs and keys only)
  • Pseudonymous usage events (an event name and timestamp, for example onboarding progress or a report being opened) and per-organization API usage counts, used to improve the product

We deliberately do not store:

  • End-user names, email addresses, or avatars: names shown in BesTest are resolved live from Jira while you use the app and never persisted by us
  • The content of your Jira issues: we keep only the reference (ID and key)
  • Atlassian credentials of any kind

4. Security measures

  • Encryption in transit (TLS) and at rest (provider-managed encryption at Supabase)
  • Tenant isolation: every database query runs under PostgreSQL Row-Level Security scoped to the requesting organization, enforced on every request, not just in application code
  • Identity: requests are authenticated with short-lived signed tokens derived from the Atlassian Forge context; API tokens for integrations are issued per organization, scoped, and revocable
  • Least privilege: services connect with minimal database roles; production access is limited to the founding team
  • Regional isolation: each hosting region is a separate database with separate credentials
  • No ad tech inside the app: no advertising trackers or third-party profiling in the product

Honesty note: as a small company we do not currently hold formal certifications such as SOC 2 or ISO 27001. We apply the industry-standard practices above, keep our attack surface small, and are happy to walk your security team through the architecture in detail.

5. GDPR compliance

  • For test management content, your organization is the controller and BT Studio acts as a processor; for account, website, and usage data, BT Studio is the controller
  • Processing rests on contract performance (providing the app), legitimate interest (security, operations, and understanding product usage), and consent where required; details in our Privacy Policy
  • A Data Processing Agreement (DPA) including Standard Contractual Clauses is available on request
  • Uninstalling BesTest leads to deletion of your instance's data from our systems within a reasonable period; deletion requests are honored per the Privacy Policy
  • BT Studio is established in Hungary (EU); our supervisory authority is the Hungarian NAIH

6. Sub-processors

For the BesTest app itself:

  • Atlassian (Forge platform: app hosting and user interface, within your Jira Cloud)
  • Supabase (managed PostgreSQL database in your selected region: EU, US, or India)
  • Cloudflare (API gateway and edge infrastructure)
  • Released.so (in-app release notes widget)

Our marketing website additionally uses analytics services (listed in the Privacy Policy); these never touch app data.

7. EULA and agreements

  • Our Terms of Service serve as the End User License Agreement (EULA) for BesTest
  • Billing and payment run through the Atlassian Marketplace and are governed by Atlassian's Marketplace Terms of Use
  • Our Privacy Policy covers data handling; a DPA is available on request

8. Regulated industries (including FINMA)

BT Studio is not a financial institution and is not directly subject to supervision by FINMA or similar financial regulators. For customers in regulated industries carrying out outsourcing or vendor due diligence (for example under FINMA guidance for Swiss financial institutions), the facts that usually matter are documented on this page: EU data hosting is available and region-pinned, data is encrypted in transit and at rest, tenants are isolated at the database level, we store a deliberate minimum of personal data (pseudonymous identifiers only), a DPA with SCCs is available, and your data is deleted when you leave. We are happy to complete security questionnaires and support your review within the limits of a small team.

9. Contact

Security questions, questionnaires, DPA requests, or anything about this page:

Beard & Tailor Studio Kft. (trading as BT Studio)
Registered in Hungary, European Union
Email: info@btstudio.io