SECURITY & DEPLOYMENT

Your test data. Your deployment choice.

Choose where the platform runs, who can access it, and the operating requirements your IT team needs to review.

Choose where your data lives.

Your tests execute at the station. You choose where their results are sent.

Managed cloud

The shared platform, operated and updated by tofupilot. Start without managing servers.

Dedicated cloud

Your own environment, managed by tofupilot. Agree the region, capacity, and operating requirements with our team.

Self-hosted

Dashboard, deployer, database, and file storage on your infrastructure. Your IT team controls the network boundary.

Compare self-hosting requirements

DATA & AI BOUNDARIES

Know where the work happens.

YOUR STATION

Execute the test.

Test code and instruments run on your bench or production station.

Results & context
YOUR CHOSEN DEPLOYMENT

Keep the record.

Store results, attachments, and unit history in the platform you selected.

When using cloud AI
SWISS CLOUD AI

Investigate the evidence.

Open-source models hosted by Infomaniak, an independent Swiss provider.

Cloud AI processing stays in Switzerland. Your prompts and test data are never used to train foundation models. Review AI connectivity separately for self-hosted and air-gapped deployments.

AI hosting & data privacy

Identity, permissions, and station access.

Use your company identity.

Connect SSO and SCIM on Enterprise. Require passkeys or authenticator-based 2FA, with recovery codes as a backup.

SSO & provisioning

Give each person a role.

Owners and Admins manage the organization. Developers maintain tests, Viewers read results, and Operators use the station interface.

Full permission matrix

Scope your credentials.

User keys inherit their owner’s permissions. Station keys are limited to their station. Review expiry, last use, and revocation in the docs.

API keys & lifecycle

Access groups organize station visibility.

Assign suppliers or teams to the stations they operate or review. Available on all plans.

Groups do not isolate test data. Owners, Admins, and Developers see all stations; records remain organization-wide for roles with read access. Operators cannot browse those records.

Viewer and Operator visibility rules

Keep a record. Plan recovery.

Review API activity.

Small request inputs may be retained. Review callers, endpoints, time, and status. Export loaded API activity as CSV; review retention and archiving requirements with our team.

Audit trail documentation

Own the operating plan.

For self-hosting, back up the database and file storage. Plan recovery, upgrades, and external connectivity, including air-gapped license activation.

Self-hosted operations

Plan a deployment your team can trust.