Third Party Index

Snapshot 17706

Document
Security page
URL
https://katalon.com/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
195708 bytes
SHA-256 (raw)
54325a49f15e447b7feea0124b2cbf338260333c79506cbc5e4ed34ff4cc6852
SHA-256 (normalized text)
2ede437bc3dc95d315ee31b3f4e5db4b9ff2956448f3a61646a8ced5c105023e

Normalized text

Scripts and page chrome removed; this is what change detection compares.

How Katalon protects your test data, your pipeline and your audit trail
Architecture, controls and regional obligations in one place - written for the security reviewer, the auditor and the buyer who has to sign.
Visit Katalon Trust Center
ISO/IEC 27001Certified
ISO/IEC 27017Certified
ISO/IEC 42001Certified · AI management
SOC 2 Type IIAttestation
GDPRProcessor · DPA available
DORARegulation · EU
Quick answers
Answers to common security questions
Your test data is stored in your organization’s selected Katalon-managed secure environment. Regional hosting options are available in the United States and Europe; availability depends on the product and deployment model.
Industry lens
See how Katalon supports security requirements in your industry
Financial services
Support regulated releases with traceable evidence and deployment options that keep execution and associated test data within your selected environment or region.
Common frameworks relevant to this industry
MAS TRMRBIDORAAPRA CPS 234PCI DSS
Deployment options you controlSelf-hosted and Docker-based local execution for runs on your own infrastructure, with regional cloud hosting as an alternative. Availability varies by product and plan.
Evidence for release decisionsExportable run history, approvals, and defect links help internal audit and regulatory teams review the evidence behind each release.
Evidence for third-party reviewThe standard Customer Data Processing Agreement is public. SOC 2 and penetration-test materials are listed in the Trust Center, with availability shown for each document.
Defence in depth
Multi-layered security and a secure SDLC
Platform layers
Infrastructure
Hardened cloud baseline, private networking, no public database endpoints, continuous configuration monitoring.
Data
AES-256 at rest, TLS 1.2 or higher in transit, and field-level encryption for credentials and secrets in test artifacts.
Identity
SSO via SAML or OIDC, SCIM provisioning, project-scoped roles, and administrator MFA through configured identity policies.
Execution
Each TestCloud session runs in an ephemeral container, isolated by organization and destroyed after the run.
Detection & response
Centralized logging and 24/7 alerting support a documented incident-response process and defined customer-notification timelines.
Secure SDLC
1Threat modelling
New services and material architectural changes undergo threat modeling before implementation begins.
2Secure code review
Code changes require peer review and pass automated SAST checks before merge.
3Dependency & SBOM
Dependencies are scanned continuously, and an SBOM is generated for each release.
4Pre-release testing
DAST and container scanning act as security gates in the release pipeline.
5Annual pentest
Independent testing with a customer-shareable summary.
6Vulnerability SLA
Critical findings are remediated within the published SLA and tracked through closure.
Need the architecture diagram?
Network, data-flow, and deployment diagrams are available in the Katalon Trust Center. Browse the Trust Center to find the relevant resources; each confidential document shows its sharing and NDA requirements.
Visit the Katalon Trust Center
Platform controls
Security controls and supporting evidence
Review the controls that protect your Katalon workspace, understand how they work, and identify the supporting evidence available for your assessment.
Control	How it is enforced	Evidence
Single sign-on	SAML 2.0 and OpenID Connect (OIDC), configured per organization	SOC 2 · CC6.1
MFA through your identity provider	Customers can enforce MFA for administrators and users through configured SSO and identity-provider policies	SOC 2 · CC6.1
Role-based access	Project- and organization-level roles help limit access based on user responsibilities	ISO 27001 · A.5.15
User provisioning	SCIM 2.0 support helps automate user provisioning and deprovisioning where configured	SOC 2 · CC6.2
Encryption at rest	Customer data is encrypted at rest using AES-256 with AWS KMS-managed keys	SOC 2 · CC6.7
Encryption in transit	Data in transit is protected with TLS 1.2 or higher	SOC 2 · CC6.7
Audit history	Available product activity and audit records support security review, compliance evidence, and investigation workflows	ISO 27001 · A.8.15
Backup & recovery	Customer data is backed up using encrypted AWS-native backup controls	SOC 2 · A1.2
Deployment
Choose the deployment model that fits your security requirements
Compare Katalon-managed and customer-controlled options to understand where test execution runs, how data is protected, and which model best fits your organization’s operating requirements.
Deployment model	Data residency	Key management	Network	AI availability
Managed cloudKatalon-operated SaaS	Regional hosting options for your Katalon environment	Katalon-managed encryption with AWS KMS	Secure cloud connectivity with allowlisting options where supported
Available when enabled by administrators
Dedicated cloud optionsAvailable by agreement	Region-specific environments are available for eligible customers	Encryption options are defined by the agreed deployment scope	Private-connectivity options are available by agreement
Configured to the customer’s governance requirements
Customer-controlled executionRuns in your infrastructure	Test execution and associated data remain in the customer-controlled environment	Customer-managed environment and key controls apply	Customer network and perimeter controls apply; some SaaS features may require connectivity
Optional, based on configuration and deployment model
Deployment, residency, networking, key-management, and AI options vary by product, region, and agreement.
Compliance support
How Katalon supports your regulatory and compliance requirements
Compliance is a shared effort. Each entry explains the customer responsibility and the Katalon capabilities or evidence that can support your compliance program.
Customer responsibilityThe requirement applies to your organizationSharedKatalon also has processor or vendor responsibilitiesIndependent assuranceIndependent evidence is available on request
AI architecture
AI privacy and control stay in your hands
Katalon AI helps teams move faster without using customer data to train AI models. AI assistance is grounded in relevant workspace context, and administrators control whether and how AI features are enabled across the organization.
Zero-data-retention agreements with Katalon-managed model providers.
Customer data, prompts, and artifacts are not used to train AI models.
Administrators can disable AI per project or across the organization.
Supported AI experiences can reference the run, test, or file used as source context.
Grounded
AI responses use relevant Katalon context - such as tests, runs, and artifacts - to provide practical, workspace-aware assistance.
Cited
AI-assisted answers can reference the source context behind the response, helping reviewers validate where an answer came from.
Controlled
Administrators manage AI availability, provider settings, and supported AI keys to align with internal security policies.
Contained
Organizations can enable, restrict, or disable AI features based on their governance, deployment, and compliance requirements.
Documentation & reports
Find the security evidence required for your review
Browse Katalon’s security, compliance, and privacy resources in the Trust Center. Public documents are available immediately. Confidential materials show a document-specific request process and any NDA requirements.
Visit Katalon Trust Center
SOC 2 Type II report By request
ISO 27001 · 27017 · 42001 certificates By request
Penetration test summary By request
Data processing agreement (standard) Public
Architecture whitepaper By request
Looking for something else? Browse the full library of security policies, control summaries, compliance documents, and completed questionnaires. Each item shows how it can be accessed.
Click
Talk to someone who knows testing
Tell us what you are trying to solve and we will bring the right specialist to the call.
A reply within one business dayA walkthrough on your own scenariosNo obligation, and no sales sequence
4.5 on G2Trusted by 30,000+ quality teams
Thank you! We will contact you soon.