Security and data

TestDetta runs in your CI and on your machines. Your source code, coverage maps and test results never leave them. This page lists everything it stores and every network call it makes.

What stays in your CI

Where it keeps files

PathContents
.testdetta/coverage/Coverage maps of the current commit, one per test project
.testdetta/cache/A cache of the evaluated project graph
.testdetta/license.jsonOptional: extra bot accounts to leave out of the committer count
~/.testdetta/licenseA license installed with td license install, or renewed automatically
~/.testdetta/license-refreshWhen the last renewal was attempted
--maps-dir folderMaps of earlier commits, one folder per commit, kept where you choose

On GitHub Actions, maps are stored in your repository's Actions cache. .testdetta/coverage/ and .testdetta/cache/ are generated; keep them out of version control.

The one network call

With a subscription license, TestDetta asks the license service for a renewed license at most once a day, so that renewals reach CI without anyone updating a secret.

Public repositories need no license and make no call.

How the license is checked

A license is a signed string, verified on your machine with a public key built into TestDetta. It names the repositories it covers, matched against the origin remote with any credentials removed first. A license problem never fails a build: every test runs instead, as before TestDetta. More about licenses.

What we keep

For a subscription: the licensee name, the repositories it covers, the number of seats and its period. The payment and the email address it is sent to are handled by Polar Software, Inc., our merchant of record. See the privacy policy.

Reporting a vulnerability

Email support@testdetta.com. Please give us time to fix it before you publish.