Hosting within the European Union, end-to-end encryption, execution engine isolation, and governance aligned with ISO/IEC 27001: details on the measures that protect your data and ensure service continuity.
Google Cloud, europe-west1 region in Belgium, multi-zone deployment.
AES-256 at rest, TLS in transit, logical separation of environments.
Reduced privileges, MFA for privileged accounts, periodic reviews.
Tracked administrative actions, centralized logs, retained for 12 months.
Daily backups, 24-hour RPO, 8-business-hour RTO.
SMSI is aligned with ISO/IEC 27001 and the GDPR, and the commitments are led by the DPA.
Mr Suricate, a French software company, operates a European SaaS platform dedicated to automated testing of web, mobile, and API applications. It is designed for professional environments where system reliability, production control, and the reduction of operational risks are key priorities.
Security, data protection, and service continuity are built in from the design phase and throughout the platform’s operation. Governance is based on an Information Security Management System (ISMS) aligned with the principles of the ISO/IEC 27001 standard.
This document is for informational purposes only and does not constitute a standalone contractual commitment. The applicable commitments are set forth in the Service Level Agreement (SLA), the Data Processing Agreement (DPA), and the platform’s general terms of use.
Hosting is provided by Google Cloud Platform.
The application architecture is deployed on a containerized infrastructure that enables scalability and service isolation. The execution engines used for automated testing are isolated from the main application environment, and outbound network traffic is controlled.
The data processed on the platform is protected by mechanisms that comply with industry standards:
These measures are designed to ensure data confidentiality, integrity, and availability.
Access to production environments is strictly controlled:
Administrative access is limited to authorized personnel responsible for operating the platform.
Operational monitoring and logging ensure the platform's traceability and stability:
This information is used for incident analysis and security investigations.
Specific measures ensure service continuity:
The incident management procedure is broken down into six steps:
Security incidents are documented and incorporated into the continuous improvement process.
Some of the services necessary for the platform to operate rely on technical service providers:
These service providers are selected based on security criteria and are bound by contract. The list of those who may be involved in providing the service is published on the “List of Subcontractors” page.
Personal data is processed in accordance with the General Data Protection Regulation (GDPR). Depending on the situation, two categories apply:
Data processing performed on behalf of clients is governed by a Data Processing Agreement (DPA).
Some of the platform's features incorporate AI-based assistance mechanisms. These mechanisms:
The applicable governance principles are detailed in a separate document: AI Governance Statement.
Security practices are regularly reviewed to take into account:
The security team responds to inquiries from clients and prospects, including security questionnaires and due diligence requests.