Security & Compliance

Trust Center

Security, privacy, compliance, and data governance practices for organizations running assessments with TestInvite.

GDPR compliant — we act as Data Processor
Hosted on FedRAMP-authorized infrastructure
Data encrypted in transit and at rest
Standard Contractual Clauses for EU data transfers
testinvite.com — Security Status
System Status
All systems operational
Data Encryption
Active
Access Control (RBAC)
Active
Audit Logging
Active
Vulnerability Management
Active
Google Cloud Infrastructure
Operational
Platform uptime (last 90 days) 99.9%
Security

Security

Data encryption

All data is encrypted both in transit and at rest. No data is exchanged or stored over unencrypted channels.

Access control

Role-based access controls ensure every user and administrator can only reach the data their role explicitly permits.

Audit logging

System-wide audit logs track data modifications and system actions. Enterprise customers can request logs related to their data in the event of an incident.

Vulnerability management

Vulnerabilities are identified, classified by severity, and remediated on structured timelines aligned with recognized industry standards.

Secure infrastructure

TestInvite is hosted exclusively on Google Cloud. All infrastructure is managed within Google's environment, we operate no proprietary data centers.

Privacy and compliance

Privacy and compliance

Regulation

GDPR compliant

TestInvite operates as a Data Processor under GDPR. Your organization retains full ownership and control of participant data as Data Controller.

Infrastructure

FedRAMP-authorized cloud

Infrastructure runs on Google Cloud services that hold FedRAMP authorization for cloud security and data protection.

International transfers

Standard Contractual Clauses

Data transfers from the EU are governed by Standard Contractual Clauses (SCCs), providing a lawful basis for international processing.

Commitment

Data confidentiality

Participant data is processed solely to deliver the assessment service. It is never shared with third parties except where required by law or necessary to operate the platform.

Data governance

Data governance

Data location

All data is stored and processed in the United States on Google Cloud infrastructure.

Data ownership

Customers act as Data Controllers. TestInvite processes data strictly as a Data Processor, only as directed by the applicable contract.

Data retention

Data retention

Fixed period
Customer-configurable
Customer data

Exam content, configurations

Content created and uploaded by administrators. Does not typically contain personal data.

Retention
1 month
After account becomes inactive
Exam response data

Candidate answers and scores

Personal data submitted by candidates during assessments.

Retention
Up to 5 years
Or on request
Customers can delete anytime
Supplementary data

Proctoring materials and session records

Recordings and other data collected during exam delivery.

Retention
1 year default
From date of collection
Enterprise customers can customize
Contact

Questions about security or privacy?

Our team is available to walk you through TestInvite's security practices, data handling procedures, or compliance documentation in detail.

Contact us