How Katalon protects your test data, your pipeline and your audit trail

Architecture, controls and regional obligations in one place - written for the security reviewer, the auditor and the buyer who has to sign.

Visit Katalon Trust Center
ISO/IEC 27001Certified
ISO/IEC 27017Certified
ISO/IEC 42001Certified · AI management
SOC 2 Type IIAttestation
GDPRProcessor · DPA available
DORARegulation · EU
Quick answers

Answers to common security questions

Your test data is stored in your organization’s selected Katalon-managed secure environment. Regional hosting options are available in the United States and Europe; availability depends on the product and deployment model.
Industry lens

See how Katalon supports security requirements in your industry

Financial services

Support regulated releases with traceable evidence and deployment options that keep execution and associated test data within your selected environment or region.

Common frameworks relevant to this industry
MAS TRMRBIDORAAPRA CPS 234PCI DSS
  • Deployment options you controlSelf-hosted and Docker-based local execution for runs on your own infrastructure, with regional cloud hosting as an alternative. Availability varies by product and plan.
  • Evidence for release decisionsExportable run history, approvals, and defect links help internal audit and regulatory teams review the evidence behind each release.
  • Evidence for third-party reviewThe standard Customer Data Processing Agreement is public. SOC 2 and penetration-test materials are listed in the Trust Center, with availability shown for each document.
Defence in depth

Multi-layered security and a secure SDLC

Platform layers

Infrastructure

Hardened cloud baseline, private networking, no public database endpoints, continuous configuration monitoring.

Data

AES-256 at rest, TLS 1.2 or higher in transit, and field-level encryption for credentials and secrets in test artifacts.

Identity

SSO via SAML or OIDC, SCIM provisioning, project-scoped roles, and administrator MFA through configured identity policies.

Execution

Each TestCloud session runs in an ephemeral container, isolated by organization and destroyed after the run.

Detection & response

Centralized logging and 24/7 alerting support a documented incident-response process and defined customer-notification timelines.

Secure SDLC
  1. 1Threat modelling

    New services and material architectural changes undergo threat modeling before implementation begins.

  2. 2Secure code review

    Code changes require peer review and pass automated SAST checks before merge.

  3. 3Dependency & SBOM

    Dependencies are scanned continuously, and an SBOM is generated for each release.

  4. 4Pre-release testing

    DAST and container scanning act as security gates in the release pipeline.

  5. 5Annual pentest

    Independent testing with a customer-shareable summary.

  6. 6Vulnerability SLA

    Critical findings are remediated within the published SLA and tracked through closure.

Need the architecture diagram?

Network, data-flow, and deployment diagrams are available in the Katalon Trust Center. Browse the Trust Center to find the relevant resources; each confidential document shows its sharing and NDA requirements.

Visit the Katalon Trust Center
Platform controls

Security controls and supporting evidence

Review the controls that protect your Katalon workspace, understand how they work, and identify the supporting evidence available for your assessment.

ControlHow it is enforcedEvidence
Single sign-onSAML 2.0 and OpenID Connect (OIDC), configured per organizationSOC 2 · CC6.1
MFA through your identity providerCustomers can enforce MFA for administrators and users through configured SSO and identity-provider policiesSOC 2 · CC6.1
Role-based accessProject- and organization-level roles help limit access based on user responsibilitiesISO 27001 · A.5.15
User provisioningSCIM 2.0 support helps automate user provisioning and deprovisioning where configuredSOC 2 · CC6.2
Encryption at restCustomer data is encrypted at rest using AES-256 with AWS KMS-managed keysSOC 2 · CC6.7
Encryption in transitData in transit is protected with TLS 1.2 or higherSOC 2 · CC6.7
Audit historyAvailable product activity and audit records support security review, compliance evidence, and investigation workflowsISO 27001 · A.8.15
Backup & recoveryCustomer data is backed up using encrypted AWS-native backup controlsSOC 2 · A1.2
Deployment

Choose the deployment model that fits your security requirements

Compare Katalon-managed and customer-controlled options to understand where test execution runs, how data is protected, and which model best fits your organization’s operating requirements.

Deployment modelData residencyKey managementNetworkAI availability
Managed cloudKatalon-operated SaaSRegional hosting options for your Katalon environmentKatalon-managed encryption with AWS KMSSecure cloud connectivity with allowlisting options where supported
Available when enabled by administrators
Dedicated cloud optionsAvailable by agreementRegion-specific environments are available for eligible customersEncryption options are defined by the agreed deployment scopePrivate-connectivity options are available by agreement
Configured to the customer’s governance requirements
Customer-controlled executionRuns in your infrastructureTest execution and associated data remain in the customer-controlled environmentCustomer-managed environment and key controls applyCustomer network and perimeter controls apply; some SaaS features may require connectivity
Optional, based on configuration and deployment model

Deployment, residency, networking, key-management, and AI options vary by product, region, and agreement.

Compliance support

How Katalon supports your regulatory and compliance requirements

Compliance is a shared effort. Each entry explains the customer responsibility and the Katalon capabilities or evidence that can support your compliance program.

Customer responsibilityThe requirement applies to your organizationSharedKatalon also has processor or vendor responsibilitiesIndependent assuranceIndependent evidence is available on request
ImageAI architecture

AI privacy and control stay in your hands

Katalon AI helps teams move faster without using customer data to train AI models. AI assistance is grounded in relevant workspace context, and administrators control whether and how AI features are enabled across the organization.

  • Zero-data-retention agreements with Katalon-managed model providers.
  • Customer data, prompts, and artifacts are not used to train AI models.
  • Administrators can disable AI per project or across the organization.
  • Supported AI experiences can reference the run, test, or file used as source context.

Grounded

AI responses use relevant Katalon context - such as tests, runs, and artifacts - to provide practical, workspace-aware assistance.

Cited

AI-assisted answers can reference the source context behind the response, helping reviewers validate where an answer came from.

Controlled

Administrators manage AI availability, provider settings, and supported AI keys to align with internal security policies.

Contained

Organizations can enable, restrict, or disable AI features based on their governance, deployment, and compliance requirements.

Documentation & reports

Find the security evidence required for your review

Browse Katalon’s security, compliance, and privacy resources in the Trust Center. Public documents are available immediately. Confidential materials show a document-specific request process and any NDA requirements.

Visit Katalon Trust Center
Available in the Trust Center5 of many
SOC 2 Type II report By request
ISO 27001 · 27017 · 42001 certificates By request
Penetration test summary By request
Data processing agreement (standard) Public
Architecture whitepaper By request

Looking for something else? Browse the full library of security policies, control summaries, compliance documents, and completed questionnaires. Each item shows how it can be accessed.