Infrastructure
Hardened cloud baseline, private networking, no public database endpoints, continuous configuration monitoring.
Architecture, controls and regional obligations in one place - written for the security reviewer, the auditor and the buyer who has to sign.
Visit Katalon Trust CenterSupport regulated releases with traceable evidence and deployment options that keep execution and associated test data within your selected environment or region.
Common frameworks relevant to this industryHardened cloud baseline, private networking, no public database endpoints, continuous configuration monitoring.
AES-256 at rest, TLS 1.2 or higher in transit, and field-level encryption for credentials and secrets in test artifacts.
SSO via SAML or OIDC, SCIM provisioning, project-scoped roles, and administrator MFA through configured identity policies.
Each TestCloud session runs in an ephemeral container, isolated by organization and destroyed after the run.
Centralized logging and 24/7 alerting support a documented incident-response process and defined customer-notification timelines.
New services and material architectural changes undergo threat modeling before implementation begins.
Code changes require peer review and pass automated SAST checks before merge.
Dependencies are scanned continuously, and an SBOM is generated for each release.
DAST and container scanning act as security gates in the release pipeline.
Independent testing with a customer-shareable summary.
Critical findings are remediated within the published SLA and tracked through closure.
Network, data-flow, and deployment diagrams are available in the Katalon Trust Center. Browse the Trust Center to find the relevant resources; each confidential document shows its sharing and NDA requirements.
Review the controls that protect your Katalon workspace, understand how they work, and identify the supporting evidence available for your assessment.
| Control | How it is enforced | Evidence |
|---|---|---|
| Single sign-on | SAML 2.0 and OpenID Connect (OIDC), configured per organization | SOC 2 · CC6.1 |
| MFA through your identity provider | Customers can enforce MFA for administrators and users through configured SSO and identity-provider policies | SOC 2 · CC6.1 |
| Role-based access | Project- and organization-level roles help limit access based on user responsibilities | ISO 27001 · A.5.15 |
| User provisioning | SCIM 2.0 support helps automate user provisioning and deprovisioning where configured | SOC 2 · CC6.2 |
| Encryption at rest | Customer data is encrypted at rest using AES-256 with AWS KMS-managed keys | SOC 2 · CC6.7 |
| Encryption in transit | Data in transit is protected with TLS 1.2 or higher | SOC 2 · CC6.7 |
| Audit history | Available product activity and audit records support security review, compliance evidence, and investigation workflows | ISO 27001 · A.8.15 |
| Backup & recovery | Customer data is backed up using encrypted AWS-native backup controls | SOC 2 · A1.2 |
Compare Katalon-managed and customer-controlled options to understand where test execution runs, how data is protected, and which model best fits your organization’s operating requirements.
| Deployment model | Data residency | Key management | Network | AI availability |
|---|---|---|---|---|
| Managed cloudKatalon-operated SaaS | Regional hosting options for your Katalon environment | Katalon-managed encryption with AWS KMS | Secure cloud connectivity with allowlisting options where supported | Available when enabled by administrators |
| Dedicated cloud optionsAvailable by agreement | Region-specific environments are available for eligible customers | Encryption options are defined by the agreed deployment scope | Private-connectivity options are available by agreement | Configured to the customer’s governance requirements |
| Customer-controlled executionRuns in your infrastructure | Test execution and associated data remain in the customer-controlled environment | Customer-managed environment and key controls apply | Customer network and perimeter controls apply; some SaaS features may require connectivity | Optional, based on configuration and deployment model |
Deployment, residency, networking, key-management, and AI options vary by product, region, and agreement.
Compliance is a shared effort. Each entry explains the customer responsibility and the Katalon capabilities or evidence that can support your compliance program.
Supervisory guidance for MAS-regulated entities: test changes to critical systems and retain evidence of the outcome before production release.
How Katalon helps: Self-hosted deployment in a region you choose, timestamped run history and release-gate reports per change record.
Auditable change management and testing before deployment. Separately, RBI’s payment-data directive requires payment system data to be stored in India.
How Katalon helps: On-premises or in-country deployment; in self-hosted mode no test data leaves your environment.
Applies to financial entities: resilience testing, an ICT third-party register and exit planning. Requirements reach vendors through your contract, not by certification.
How Katalon helps: Resilience regression suites and documentation that supports your ICT third-party register are available through product evidence and Trust Center resources.
You are the controller; Katalon acts as processor for the personal data you choose to process. Lawful basis and data minimization stay with you.
How Katalon helps: DPA with Art. 28 terms, EU data region, and guidance for keeping personal data out of test fixtures.
APRA-regulated entities must assess the information security capability of material service providers and test control effectiveness systematically.
How Katalon helps: Pentest summary, control mapping and an evidence pack for your assessment file.
Bank Negara Malaysia’s Risk Management in Technology policy requires financial institutions to test changes before production, assess third-party technology providers and control where data is hosted.
How Katalon helps: Self-hosted or in-region deployment, release-gate evidence per change, and a security documentation pack for your third-party assessment.
You are the data user; Katalon acts as data processor for the personal data you choose to process. Breach notification and DPO duties sit with you.
How Katalon helps: Standard public data processing agreement and guidance for keeping personal data out of test fixtures.
Technology risk principles for authorized institutions: independent testing and formal sign-off before deploying changes to customer-facing systems.
How Katalon helps: Segregated approver roles, run records tied to approvals and an exportable sign-off trail.
Covered financial entities must run a written cybersecurity program, assess third-party service providers and keep audit trails of material changes.
How Katalon helps: Control mapping, pentest summary and exportable run and approval records for your third-party assessment file.
US banking supervisors and the FTC Safeguards Rule expect documented change testing, vendor oversight and protection of customer information.
How Katalon helps: Release-gate evidence per change and Trust Center security documentation support vendor due diligence.
Federally regulated financial institutions must manage technology and cyber risk across the lifecycle, including testing before release and third-party risk assessment.
How Katalon helps: Self-hosted or Canadian-region deployment, documented test evidence and a control mapping for your assessment.
You are the controller for personal data; Katalon acts as operator for the data you choose to process. Lawful basis and minimization stay with you.
How Katalon helps: Standard public data processing agreement and guidance for keeping personal data out of test fixtures.
Live PANs must not be used in test or development environments (Req. 6.5.5); changes require documented testing.
How Katalon helps: Tokenized test-data guidance and network isolation for payment regression suites.
Your vendor file needs evidence that Katalon’s own security controls operate effectively.
How Katalon helps: Current certificates and the SOC 2 Type II report are listed in the Trust Center, where each document shows its availability and any NDA requirement.
Katalon AI helps teams move faster without using customer data to train AI models. AI assistance is grounded in relevant workspace context, and administrators control whether and how AI features are enabled across the organization.
AI responses use relevant Katalon context - such as tests, runs, and artifacts - to provide practical, workspace-aware assistance.
AI-assisted answers can reference the source context behind the response, helping reviewers validate where an answer came from.
Administrators manage AI availability, provider settings, and supported AI keys to align with internal security policies.
Organizations can enable, restrict, or disable AI features based on their governance, deployment, and compliance requirements.
Browse Katalon’s security, compliance, and privacy resources in the Trust Center. Public documents are available immediately. Confidential materials show a document-specific request process and any NDA requirements.
Looking for something else? Browse the full library of security policies, control summaries, compliance documents, and completed questionnaires. Each item shows how it can be accessed.