Security and privacy
at Gatling

Gatling is SOC 2 Type II certified. Performance testing means handling your systems, your traffic patterns, and sometimes your production-adjacent data. We build Gatling with security, privacy, and transparency at its core, from infrastructure to product features, so your load tests stay reliable without becoming a liability.

Certifications & Compliance


Independently audited. Continuously maintained.

SOC 2 Type II

Gatling's own security, availability, and confidentiality controls, audited by Bastion Technologies, covering a sustained period of operation, not a single point in time.

GDPR & CNIL compliant

Data processed in line with EU and UK privacy regulations.

AWS infrastructure compliance

Gatling is hosted on AWS, which itself holds ISO 27001, SOC 2, PCI DSS Level 1, and HDS certifications.

Trusted by industry leaders

300.000+ organizations

From government agencies to fintech startups, organizations across 30+ industries rely on Gatling to validate mission-critical systems. Our platform supports some of the world’s most security-sensitive environments, including finance, healthcare, energy, and aerospace, where performance and compliance go hand in hand.

1 million+ users in 65+ countries

Gatling’s global community of developers, QA engineers, and performance specialists contributes to and benefits from a constantly improving ecosystem. Whether in Europe, the US, or Asia-Pacific, teams use Gatling to standardize testing practices, accelerate release cycles, and share knowledge worldwide.

30 million downloads since launch

Gatling has proven its reliability and scalability in real-world projects. This adoption reflects years of continuous innovation, active community support, and trust from enterprises that integrate Gatling at the heart of their DevOps and testing strategies.

Our security program

Data protection

Encryption in transit

All traffic is encrypted in transit using TLS, with configurations audited quarterly against industry benchmarks (SSL Labs) and any grade below A promptly corrected.

Encryption at rest

All stored data is encrypted at rest, with database and file storage layers using at minimum block-level or provider-managed encryption.

Secrets management

Gatling Enterprise Edition integrates with tools like AWS Secrets Manager to securely handle API keys and credentials.

Infrastructure security

Hosting

AWS Europe (Paris Region), isolated multi-tenant VPC architecture.

High availability

Multi-AZ replication and automated failover.

AWS compliance

Our hosting provider holds ISO 27001, SOC 2, PCI DSS Level 1, and HDS certifications.

DDoS protection

AWS WAF deployed at every edge location.

Backups & recovery

Automated daily backups, encrypted and replicated to a geographically independent region, with an annual disaster recovery test against a defined RTO.

Vendor risk management

All vendors are inventoried and classified by data sensitivity. Vendors handling sensitive data undergo risk assessment, with ongoing monitoring of their security posture.

Product & application security

Penetration testing

Annual penetration tests conducted by independent third-party security experts. Critical and high-severity findings are resolved promptly; others are prioritized accordingly.

Vulnerability scanning

Integrated into our secure development lifecycle (SDLC).

Endpoint protection

All corporate devices run hardened configurations, disk encryption, and anti-malware.

Identity & access management

Role-based access, SSO integration, and automatic deprovisioning on employee departure.

Secure remote access

Access to internal systems requires SSO and multi-factor authentication, following the principle of least privilege.

Compliance & privacy

GDPR & CNIL

Data processed in line with EU and UK privacy regulations.

SOC 2 Type II certified

Transparent policies

Clear, accessible policies that explain how your data is handled and what rights you have over it.

Cyber insurance

Gatling maintains cyber insurance coverage to mitigate the financial impact of security incidents.

Continuous monitoring & responsible disclosure


We use advanced logging and monitoring to detect anomalies, track audit trails, and respond quickly to potential threats. Security incidents are formally tracked through a dedicated incident management program, from detection to resolution and post-mortem review. Our security posture is reviewed on an ongoing basis, not just at audit time.

No system is impenetrable. We continually refine our security practices and welcome collaboration from the community.

If you discover a potential issue,
please contact us.

Evaluating Gatling for a security-sensitive deployment?

Our team can share our SOC 2 report, security questionnaires, and policy documentation directly on request.