TRUST CENTER

Overview of Security

Hosting within the European Union, end-to-end encryption, execution engine isolation, and governance aligned with ISO/IEC 27001: details on the measures that protect your data and ensure service continuity.

SMSI Compliant with ISO/IEC 27001·Hosting in the European Union·GDPR-compliant
Updated: September 8, 2026 · Informational document; has no independent contractual value
AT A GLANCE

Measures Currently in Place

Infrastructure

Google Cloud, europe-west1 region in Belgium, multi-zone deployment.

Encryption

AES-256 at rest, TLS in transit, logical separation of environments.

Access

Reduced privileges, MFA for privileged accounts, periodic reviews.

Logging

Tracked administrative actions, centralized logs, retained for 12 months.

Continuity

Daily backups, 24-hour RPO, 8-business-hour RTO.

Compliance

SMSI is aligned with ISO/IEC 27001 and the GDPR, and the commitments are led by the DPA.

1Introduction

Mr Suricate, a French software company, operates a European SaaS platform dedicated to automated testing of web, mobile, and API applications. It is designed for professional environments where system reliability, production control, and the reduction of operational risks are key priorities.

Security, data protection, and service continuity are built in from the design phase and throughout the platform’s operation. Governance is based on an Information Security Management System (ISMS) aligned with the principles of the ISO/IEC 27001 standard.

This editorial stance is also a public commitment: we outline it in our manifesto, “The Trusted Third Party for Your Critical Journeys.”

PLEASE NOTE

This document is for informational purposes only and does not constitute a standalone contractual commitment. The applicable commitments are set forth in the Service Level Agreement (SLA), the Data Processing Agreement (DPA), and the platform’s general terms of use.

2Cloud Infrastructure

Hosting is provided by Google Cloud Platform.

  • Primary region: europe-west1, in Belgium
  • Multi-zone deployment
  • Infrastructure located within the European Union

The application architecture is deployed on a containerized infrastructure that enables scalability and service isolation. The execution engines used for automated testing are isolated from the main application environment, and outbound network traffic is controlled.

3Data Protection

The data processed on the platform is protected by mechanisms that comply with industry standards:

  • Encryption of data at rest (AES-256)
  • Encryption of Communications in Transit (TLS)
  • Logical Separation of Environments
  • Secure Credential and Access Management
  • Periodic Rotation of Sensitive Access Points

These measures are designed to ensure data confidentiality, integrity, and availability.

4. Access Management

Access to production environments is strictly controlled:

  • Principle of Least Privilege
  • Centralized Access Management
  • Multifactor Authentication (MFA) for Privileged Accounts
  • Periodic Review of Sensitive Accesses

Administrative access is limited to authorized personnel responsible for operating the platform.

5Workplace Safety

The workstations used to access the systems are subject to security measures appropriate to the level of risk.

  • Active antivirus software that is kept up to date.
  • Automatic updates for the operating system and software.
  • Automatic session lock.
  • Centralized asset inventory and individual assignment.
  • Onboarding and offboarding procedures governing the granting and revocation of access.
  • Prohibition on storing customer data on personal devices.
  • Do not use unsecured public Wi-Fi networks.

Comprehensive encryption of storage media and centralized management of the device fleet are priority objectives of our information security management system, as outlined in our continuous improvement plan.

6Monitoringand Logging

Operational monitoring and logging ensure the platform's traceability and stability:

  • Logging of administrative actions
  • Monitoring of Technical and Safety Events
  • Centralization of Technical Logs
  • Retention of logs for 12 months

This information is used for incident analysis and security investigations.

7Business Continuity

Specific measures ensure service continuity:

  • Daily Backups
  • Backup Retention Policies
  • Periodic Restore Tests
INDICATIVE OBJECTIVES
24 hoursRPO — maximum data loss
8 a.m.RTO — time to restore service, in business hours

8Incident Management

The incident management procedure is broken down into six steps:

  1. Detection
  2. Qualification
  3. Lockdown
  4. Remediation
  5. Notify the customer when necessary
  6. Post-incident Analysis

Applicable time limits, calculated from the date of detection unless otherwise specified:

  • Incident classification: 4 hours.
  • Lockdown: 8 hours.
  • Notification to the customer of any security incident affecting them: no later than 24 hours after verification.
  • Notification of a personal data breach: without undue delay after becoming aware of and assessing the breach, in accordance with the terms of the data processing agreement. The procedural deadline is set at 72 hours.
  • Initial report: 24 hours.
  • Post-incident report: 5 business days.

Shorter contractual deadlines may be agreed upon. The enforceable obligations are set forth in the service agreement and the data processing agreement.

Security incidents are documented and incorporated into the continuous improvement process.

9Vulnerability Management

A formalized process governs the detection, assessment, and remediation of vulnerabilities.

  • Regular updates to servers, systems, and dependencies.
  • Tracking software versions, published vulnerabilities, and end-of-life dates.
  • Review of open-source dependencies.
  • Annual penetration test conducted by a qualified PASSI third-party service provider.
  • Vulnerability Registry and Remediation Tracking.

Correction Deadlines by Severity:

  • Review: 48 Hours.
  • High: 7 days.
  • Average: 30 days.
  • Low: Scheduled as part of the maintenance cycle.

10Third-Party Providersand Services

Some of the services necessary for the platform to operate rely on technical service providers:

  • Cloud Infrastructure Providers
  • Mobile Testing Platforms
  • Communication Services
  • DNS and Network Services

These service providers are selected based on security criteria and are bound by contract. The list of those who may be involved in providing the service is published on the “List of Subcontractors” page.

11Data Protectionand the GDPR

Personal data is processed in accordance with the General Data Protection Regulation (GDPR). Depending on the situation, two categories apply:

  • Data Controller for Certain Internal Activities
  • Subcontractor for the provision of the SaaS platform

Data processing performed on behalf of clients is governed by a Data Processing Agreement (DPA).

12Governanceof Artificial Intelligence

Some of the platform's features incorporate AI-based assistance mechanisms. These mechanisms:

  • Remain under human supervision
  • Do not generate automated legal decisions
  • The following are included in the WSIS risk analysis:

The applicable governance principles are detailed in a separate document: AI Governance Statement.

13Continuous Improvement

Security practices are regularly reviewed to take into account:

  • Technological Advances
  • Regulatory developments
  • Operational Feedback
  • The Results of the Risk Analyses

Our commitment as a trusted third party and what it entails are detailed on a dedicated page.

A question about our safety?

The security team responds to inquiries from clients and prospects, including security questionnaires and due diligence requests.