Test data and shared reports
Choose appropriate test data and understand what a public evidence link exposes.
Scans and runs produce evidence from the target application. That evidence can include screenshots, displayed text, request details, submitted test values, and recordings where enabled.
Use suitable test data
Prefer dedicated staging accounts and disposable records. Avoid putting production passwords or customer records into reusable examples, CSV files, or publicly shared demonstrations.
Store target logins in App access and secret configuration in Variables and secrets. Credentials for your AI provider and CI pipeline serve different purposes and should stay in their respective configuration and secret stores.
Review a report before sharing
A public run link can be viewed by anyone who has it. Inspect the screenshots, recordings, errors, and values before distributing the link.
Use a private investigation or an exported report with an appropriate audience when the evidence contains information that should not be public. A report's readability does not establish that its contents are suitable for sharing.
Retention and deletion
Consult the current plan and Privacy policy for applicable retention and data-handling terms. Deleting a test case, a project, and a downloaded report are distinct actions; copies outside AegisRunner remain under their holders' control.
For an account or data request, contact Support with the resource and account identifiers needed to investigate, without including account passwords or tokens.