Katalon Trust Center

Trust is our foundation

Welcome to the Katalon Trust Center. Discover how we protect your data through our commitment to enterprise-grade security, verifiable compliance, and responsible AI.

Icon_shield

Security

Learn about our robust security program, from our secure development practices to our resilient cloud infrastructure.

Icon_checkbadge

Compliance

Review our certifications and attestations, including SOC 2 and ISO 27001, which are verified by independent auditors.

Icon_lock

Data & privacy

Understand our data handling practices, our commitment to global privacy standards, and our transparent approach to AI.

Security

A multi-layered security program

Our commitment to protecting your data through a robust, multi-layered security program.

Secure by design

Security isn’t an afterthought; it’s built into every phase of the software lifecycle. We embed security controls from initial design to deployment.

Infrastructure security

We host on Amazon Web Services (AWS), leveraging its resilient, globally certified infrastructure to ensure availability and protect your data.

Platform security

Sensitive data is encrypted in transit Katalon protects customer data with strong encryption (AES-256 at rest, TLS in transit), enterprise-grade identity and access controls (SSO, MFA, least privilege), and regular independent audits and penetration tests to validate our security posture.

AI security and trust

Our AI features are built on a foundation of trust and transparency, with a core commitment to zero data retention. Customer data is never retained or used by third-party providers to train their models.

Katalon’s “secure by design” philosophy

We embed controls across the software lifecycle and cloud platform so every release inherits the same hardened baseline.

Secure by design illustration

1. Plan

Security, privacy, and compliance requirements are defined at project inception.

2. Design

We conduct threat modeling (e.g., STRIDE) to address architectural risks before coding begins.

3. Develop

Engineers follow OWASP-based secure coding standards, with mandatory peer reviews and automated dependency scanning.

4. Test & verify

Static and dynamic application security testing (SAST/DAST) are integrated into our CI/CD pipeline.

5. Deploy & harden

Infrastructure as Code (IaC), least privilege access, and secure configurations are enforced in production.

6. Maintain & monitor

Continuous monitoring, vulnerability management, and a dedicated incident response team ensure ongoing protection.


Compliance

Compliance & certifications

Our commitment to global security and privacy standards

SOC 2 Type II

Katalon undergoes annual, independent third-party audits to certify our platform against the SOC 2 Type II standard for Security, Availability, and Confidentiality.

ISO/IEC 27001:2022

We are certified against the global standards for Information Security Management Systems (ISMS), demonstrating a systematic approach to managing security.

Global privacy standards

We are committed to global privacy regulations, including GDPR. We are a participating member of the EU-U.S. Data Privacy Framework (DPF) for trusted international data transfers.

AI governance & transparency

Our AI architecture provides clear, transparent documentation on how our AI systems work, the data they use, and the safeguards in place to ensure responsible operation.

Vendor security and supply chain

Your trust in Katalon extends to the vendors and sub-processors we partner with. We maintain a formal vendor security risk management program that includes rigorous initial due diligence and ongoing monitoring of all sub-processors, such as AWS and OpenAI, to ensure they meet our high security and compliance standards. This program is audited as part of our SOC 2 certification.


Data & Privacy

Your data, your control

How we handle your data with the care and control you expect.

Data ownership

You retain ownership of your data processed on the Katalon Platform. For AI-powered features, this extends to both the inputs you provide and the outputs generated by the system. Katalon acts solely as a processor, handling your data in accordance with our agreements and applicable data protection laws.

Data hosting and processing

All customer data is processed and stored in our secure AWS environment, hosted in the us-east-1 (USA) region. We apply enterprise-grade security controls to protect your data at rest and in transit.

AI trust and privacy

Our core commitment is Zero Data Retention. Your data is never used to train third-party AI models. We provide you with full control to enable, disable, and configure AI features.

Legal & DPA

We provide a GDPR-compliant Data Processing Agreement (DPA) to all customers. Find our standard DPA and other legal documentation in our central resource hub.

    AI architecture: Katalon TrueTest

    Transparency in how we leverage AI to revolutionize test automation.

Our AI trust principles

Transparency is a core component of responsible AI. We provide clear documentation about how our AI systems work, the data they use, and the safeguards we've implemented to protect your information and intellectual property.

Zero data retention

Your data is never used to train our AI models or third-party models.

Customer control

AI features are optional and can be enabled or disabled at an organizational level.

Transparency

We are committed to being transparent about how our AI features work.

Accountability

Robust internal governance ensures our AI systems are developed and deployed responsibly and ethically.

Resources

Downloads and reports

Access key documents, policies, and reports to support your due diligence process. We are committed to providing you with the information you need, when you need it.

Public documents

These documents are available for direct download.

icon-magic.

Security and trust executive summary

A high-level overview of our security program.

icon-magic.

Consensus Assessments Initiative Questionnaire (CAIQ)

Our responses to the CSA's industry-standard questionnaire.

icon-magic.

Katalon data & AI trust FAQs

Frequently asked questions.

Compliance reports & certifications

Access to our sensitive compliance reports is managed through a secure portal to protect confidentiality.

icon-magic.

SOC 2 Type II report

Our full audit report covering Security, Availability, and Confidentiality. Access requires an NDA.

icon-magic.

ISO/IEC 27001 certificate

Our official certification for Information Security Management Systems (ISMS). Access is through our portal.

icon-magic.

ISO/IEC 27017 certificate

Our official certification for Cloud Service Security. Access is through our portal.

Please visit the Katalon Security Policy Center for additional documentation

For a detailed review of our information security policies and controls, please visit our Drata-powered trust portal.

Click