Security and privacy
at Gatling
Gatling is SOC 2 Type II certified. Performance testing means handling your systems, your traffic patterns, and sometimes your production-adjacent data. We build Gatling with security, privacy, and transparency at its core, from infrastructure to product features, so your load tests stay reliable without becoming a liability.


Certifications & Compliance
Independently audited. Continuously maintained.
SOC 2 Type II
Gatling's own security, availability, and confidentiality controls, audited by Bastion Technologies, covering a sustained period of operation, not a single point in time.
GDPR & CNIL compliant
Data processed in line with EU and UK privacy regulations.
AWS infrastructure compliance
Gatling is hosted on AWS, which itself holds ISO 27001, SOC 2, PCI DSS Level 1, and HDS certifications.
Trusted by industry leaders
300.000+ organizations
From government agencies to fintech startups, organizations across 30+ industries rely on Gatling to validate mission-critical systems. Our platform supports some of the world’s most security-sensitive environments, including finance, healthcare, energy, and aerospace, where performance and compliance go hand in hand.
1 million+ users in 65+ countries
Gatling’s global community of developers, QA engineers, and performance specialists contributes to and benefits from a constantly improving ecosystem. Whether in Europe, the US, or Asia-Pacific, teams use Gatling to standardize testing practices, accelerate release cycles, and share knowledge worldwide.
30 million downloads since launch
Gatling has proven its reliability and scalability in real-world projects. This adoption reflects years of continuous innovation, active community support, and trust from enterprises that integrate Gatling at the heart of their DevOps and testing strategies.
Our security program
Governance & leadership
Our executive team is directly accountable for information security. They establish policies, monitor compliance, and drive continuous improvement of our controls.
Defense-in-depth
Layered security measures across infrastructure, processes, and people: multiple lines of defense protect your data, so no single control failure exposes you.
Principle of least privilege
Access to systems and data is strictly limited to those with a verified business need, reviewed on an ongoing basis.
Data protection
Encryption in transit
All traffic is encrypted in transit using TLS, with configurations audited quarterly against industry benchmarks (SSL Labs) and any grade below A promptly corrected.
Encryption at rest
All stored data is encrypted at rest, with database and file storage layers using at minimum block-level or provider-managed encryption.
Secrets management
Gatling Enterprise Edition integrates with tools like AWS Secrets Manager to securely handle API keys and credentials.
Infrastructure security
Hosting
AWS Europe (Paris Region), isolated multi-tenant VPC architecture.
High availability
Multi-AZ replication and automated failover.
AWS compliance
Our hosting provider holds ISO 27001, SOC 2, PCI DSS Level 1, and HDS certifications.
DDoS protection
AWS WAF deployed at every edge location.
Backups & recovery
Automated daily backups, encrypted and replicated to a geographically independent region, with an annual disaster recovery test against a defined RTO.
Vendor risk management
All vendors are inventoried and classified by data sensitivity. Vendors handling sensitive data undergo risk assessment, with ongoing monitoring of their security posture.
Product & application security
Penetration testing
Annual penetration tests conducted by independent third-party security experts. Critical and high-severity findings are resolved promptly; others are prioritized accordingly.
Vulnerability scanning
Integrated into our secure development lifecycle (SDLC).
Endpoint protection
All corporate devices run hardened configurations, disk encryption, and anti-malware.
Identity & access management
Role-based access, SSO integration, and automatic deprovisioning on employee departure.
Secure remote access
Access to internal systems requires SSO and multi-factor authentication, following the principle of least privilege.
Compliance & privacy
GDPR & CNIL
Data processed in line with EU and UK privacy regulations.
SOC 2 Type II certified
Transparent policies
Clear, accessible policies that explain how your data is handled and what rights you have over it.
Cyber insurance
Gatling maintains cyber insurance coverage to mitigate the financial impact of security incidents.
Continuous monitoring & responsible disclosure
We use advanced logging and monitoring to detect anomalies, track audit trails, and respond quickly to potential threats. Security incidents are formally tracked through a dedicated incident management program, from detection to resolution and post-mortem review. Our security posture is reviewed on an ongoing basis, not just at audit time.
No system is impenetrable. We continually refine our security practices and welcome collaboration from the community.
If you discover a potential issue,
please contact us.
Evaluating Gatling for a security-sensitive deployment?
Our team can share our SOC 2 report, security questionnaires, and policy documentation directly on request.
