The strongest control is a wall, not a promise.
Cloud testing vendors ask you to trust their security. RobusTest removes the question: the platform, the devices, and every byte of test data stay inside your network — air-gapped entirely, if that's your requirement.
Nothing to exfiltrate, because nothing leaves.
Your data belongs to you — by policy and by architecture
We neither control nor view your data, and our policy states it plainly: everything the lab produces is yours. Builds, screenshots, logs, HAR captures, performance data, and the database itself stay on the lab servers inside your premises, behind your firewall — we supply and set up that hardware, but the data on it belongs to you, and there is no vendor cloud in the data path.
Runs fully offline
The platform operates with zero outbound connectivity for environments that require it — licensing and updates are handled offline, and regulated teams run this way today.
Secure tunnels between labs
Remote device nodes connect to the central server over authenticated tunnels — no inbound firewall holes at branch sites.
Standard controls, verifiable in your own deployment.
Single sign-on
OAuth2 sign-in with Google and Microsoft accounts, with signup restricted to the email domains you allow. Local accounts support confirmation, lockout, and recovery flows.
Transport encryption
TLS 1.2+ with a modern cipher suite for all browser and API traffic; certificates are yours to issue and rotate.
Session & form protection
CSRF tokens on state-changing requests, secure cookie-based sessions, and salted password hashing for local credentials.
API access keys
Per-user API keys for CI and scripting, revocable and regenerable at any time without touching the user's login.
Certificate-based device trust
Managed iOS devices authenticate with client certificates issued by the platform's built-in SCEP certificate authority.
Licensing & seat control
Device seats are enforced by license; node agents authenticate with license keys before they can join the lab.
A lab you can account for.
Every device and node action leaves a trail: connection and disconnection history, device lifecycle events, power actions, and per-user usage records — queryable from the admin console for incident review and capacity planning.
- Device and node connection histories
- Device activity and lifecycle event timelines
- Power-control action history
- Per-user, per-project, and per-device usage records
Straight answers for your review.
SSO today is OAuth2 (Google and Microsoft). If your organization requires a different identity provider or a formal compliance attestation, ask us — we'd rather scope it honestly than promise it on a webpage. Because the deployment is on-premise, your existing certifications and controls govern the environment the lab runs in.
Bring your security team to the demo.
We're happy to walk through deployment topology, authentication, and data flows with the people who will actually review them.