Device Test Bench

Security and Privacy

Technical boundaries used to keep device tests private and the site secure.

Last reviewed 2026-08-27

Local processing boundary

Public test JavaScript has no endpoint for sending key content, pointer coordinates, media frames, audio samples, snapshots, gamepad IDs or controller inputs. Anonymous event collection accepts only a small allowlist and stores aggregate counters.

Application security

PDO prepared statements, password hashing, CSRF tokens, secure session cookies, output escaping and administrator audit logs protect the management surface. Production errors do not expose database details or stack traces.

Browser protections

HTTPS enables protected media APIs. HSTS, Content Security Policy, Referrer Policy, nosniff, frame restrictions and Permissions Policy reduce common browser risks. Fullscreen and media permissions remain user controlled.

Advertising boundary

Ads are disabled by default. When enabled, language eligibility, page eligibility, consent and publisher configuration are checked before loading. Test pads, permission prompts, fullscreen routes, results, search, errors and admin screens remain ad-free.

Search