Testmera / FAQ

Questions before
you begin.

What to expect from a scoped, independent assessment — and how to read the result.

How independent is Testmera?

Testmera has no lab affiliation and no conflicts of interest to declare. We review potential conflicts before accepting an engagement. Fees do not determine the verdict; the agreed scope and evidence do.

What do you test?

We assess RL training environments and graders against agreed categories, including grading integrity and environment boundaries. The report states coverage, unknowns and exclusions. Public descriptions do not disclose assessment methods or third-party project results.

How do you handle data and confidentiality?

We agree confidentiality, authorised access, permitted data, storage location and retention before assessment. Detailed findings are shared privately with authorised recipients. Start by emailing a non-sensitive description; arrange a secure channel before sharing sensitive material. Website and enquiry data are covered by our privacy notice.

Can the assessment run on-premises or in the EU?

Yes, these are deployment options to scope with us. Work can run on our isolated infrastructure, inside your controlled environment, or in an agreed EU-sovereign arrangement. Region, operator control, access restrictions and evidence handling are confirmed before work begins.

How does responsible disclosure work?

We coordinate privately with affected owners and allow time for investigation and remediation before publication. Before coordinated disclosure, public material stays at category level: no third-party identifiers, project measurements or assessment methods. Security concerns about Testmera can be reported through our security policy.

Will the tooling be open source?

Open-source defensive tooling is planned. The release scope and timing will depend on responsible-disclosure review. No release date or current public availability is promised.

What does a badge mean?

A badge communicates the latest supported assessment status for a specific scope and configuration. Read it with the report, assessment date, coverage and limits. Changes can invalidate the status or require reassessment; a badge is not a general endorsement of an organisation.

What does a badge not mean?

It does not guarantee that a system is secure, correct, free of all weaknesses, legally compliant or safe for every use. PASS applies only to the assessed criteria. Unknown or unassessed areas are not passes; a signature establishes the origin and integrity of a report, not universal safety.

How long does an engagement take?

Allow roughly 2–5 working days for scoping, 1–3 weeks for assessment and reporting once setup is ready, and 3–10 working days for re-certification after fixes are ready. These are planning ranges; access, complexity and remediation affect timing. See how it works.

For an enquiry, email hello@testmera.com.