When you trust Surfshark Antivirus to protect your system, you aren’t just trusting a piece of software — you’re trusting the entire deployment pipeline that keeps that software updated against ever-evolving threats.
That’s why we’re sharing a detailed look at our SDP (Safe Deployment Practices). These protocols represent our commitment to technical transparency, ensuring that every update is stable, secure, and reliable.
Note: The core of our antivirus engine is powered by the Avira Endpoint Protection SDK, which provides its own specialized services and kernel drivers. View Avira’s SDP for more information, including details on engine, VDF (Virus Definition File), and security intelligence rollout.
Development and code integrity
Before a single line of code is deployed, it undergoes a multi-layered vetting process designed to catch vulnerabilities at the source. We prioritize a “safety-first” development cycle that balances innovation with system stability through the following:
- Multi-peer code review: every merge request requires approval from at least two peers. As an extra safety check, we also use AI-assisted code reviews in our CI (Continuous Integration) pipeline;
- Unit testing: new functionality is paired with unit tests to ensure correctness at the component level. These tests execute automatically as part of the build pipeline. Failures prevent code from being merged, catching regressions early;
- Static testing: security-focused static analysis is integrated into the build pipeline and runs automatically on every merge request to identify potential vulnerabilities before compilation;
- Kernel risk mitigation and driver certification: our drivers are “demand-start” only to minimize the kernel footprint. All drivers undergo regression testing and are certified through Microsoft’s signing process.
Internal testing
We replicate real-world usage scenarios through a series of internal testing phases:
- Build-time testing: unit tests run as part of the standard build pipeline for every merge request. Any failure automatically blocks the pipeline, preventing unverified code from moving forward;
- Functional testing: automated integration and end-to-end tests verify that all features work together as intended. These tests run twice daily and before every release, covering key user flows across the entire product;
- Compatibility testing: we run automated and manual tests across multiple hardware and software configurations. This ensures full compatibility for x64 and ARM64 systems running Windows 10 through Windows 11;
- Pre-release testing: before a release is approved, QA manually tests each individual change. Once changes are collected, we execute a full suite of unit, integration, and end-to-end tests along with targeted regression testing in affected areas.
Beta program
A critical part of safe deployment is a slow rollout that ensures a build is healthy outside of a controlled environment before it reaches our entire community.
We maintain a beta channel with approximately 30,000 active participants who opt in to early versions through app settings. This community provides early feedback via a dedicated Discord channel, allowing us to catch edge cases before a wider release.
Staged rollout
Once a build passes the beta phase, it’s deployed incrementally to ensure controlled distribution.
We move from 1% to 10%, then to 50%, and finally to 100% of our user base, closely monitoring telemetry at each percentage jump. If an issue is detected, we can halt the rollout server-side instantly or use feature flags to remotely disable specific components.
Antivirus engine and security intelligence updates follow Avira’s own staged deployment practices. We mirror these updates through our own servers to provide an additional layer of security. If a faulty engine update is identified, Surfshark can remotely halt distribution to its users until the issue is resolved.
Monitoring
Surfshark maintains continuous monitoring throughout and after each release cycle. Crashes, errors, and events are tracked from the moment a release begins rolling out. If new issues are detected, they’re addressed immediately.
On a daily basis, our team monitors the latest release regardless of rollout stage, reviewing product metrics, user complaints, diagnostic reports, crash data, and error events to proactively identify and resolve potential issues.
Communication channels
We ensure that vital information reaches our users through multiple dedicated channels:
- In-app notifications: critical issues or system errors are communicated directly to users via in-app messages;
- Beta community: beta users can provide direct feedback and report issues to our development team through a dedicated Discord channel at https://discord.com/invite/surfshark;
- Live support: users can get 24/7 chat and email support and access troubleshooting guides on Surfshark’s dedicated support page at https://support.surfshark.com.
Surfshark’s commitment to excellence
While no deployment system can prevent every possible failure, Surfshark’s layered quality process is designed to proactively identify and address issues before they impact our users. We remain committed to continuously improving these practices to provide the most stable and secure experience possible.