Security and data handling
Built for an enterprise security review
Your documents rest and are processed in the EU. Two delivery models, access scoped per project, and an append-only record of every action — human or machine.
Test cases come from your documents, not from the model
Three facts about what happens to your material when a case is generated.
Source
Every case cites the document and section behind it
Grounded in your indexed documents, not the model’s prior knowledge — and a case the documents don’t support isn’t produced.
Training
We do not train models on your documentation
Not by us, and not by the model provider. Your material never enters a training set on either side.
Retention
The model provider keeps nothing
Only the part of a document a step needs is sent, and the gateways are configured for zero retention — the provider keeps none of it.
What each person can reach, and what each run can do
Two controls on what your people can reach, and two on what a run can do unattended.
Access is scoped per project, and per role inside it
A person reaches the projects they are on, and inside those, only what their role allows.
Your own identity provider, through SSO and OIDC
Microsoft Entra ID is supported today. On private deployment you authenticate against your own directory.
A run stops itself before it crosses your limit
Set a ceiling per team and per person. A run stops itself before crossing it — so nothing here quietly becomes expensive.
Nothing acts without being written down
Append-only and captured automatically, with agent actions attributed separately from human ones. Implemented to ALCOA+ principles.
Two models. Pick where your documents sit.
Where your documents sit, and who runs the environment they sit in, differ between the two.
SaaS
Runs on infrastructure we operate
Private deployment
Runs inside your perimeter
Secured infrastructure we operate ourselves, in the EU. Not handed to anyone else.
Your environment. Nothing leaves your perimeter.
Nothing to install. You sign in and start.
We install it alongside your infrastructure, identity and security teams — then it is yours to run. Two to four weeks, most of it your own review.
EU. Your documents rest in the European Union.
Wherever your environment already is — you do not have to ask us where anything sits.
EU. Inference runs in EU regions — the processing follows the data.
Inside your perimeter. With your own model, nothing is sent out at all.
SSO / OIDC via Microsoft Entra ID.
Your identity provider.
A frontier model on an enterprise gateway — AWS Bedrock, Azure OpenAI or Google Vertex AI. We are not tied to one vendor.
Bring your own LLM — or run on the same gateways, from inside your tenant.
You can show an auditor the evidence itself
On private deployment there is also no new environment to assess. Testuvion runs inside the perimeter your own controls and reviews already cover. Testuvion produces the evidence. Your auditor draws the conclusion.
Exported from your own tenant
- Sourced test cases
- Demonstrable coverage
- A full activity log
Bundled with a manifest and a verification step.
Ask us what this page doesn’t cover
Whatever your security review asks that this page doesn’t answer — send it. We reply within 24 business hours.
