> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://katalyz.crisp.help/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How we protect your data

Your data deserves serious protection — especially when you're signing contracts, sharing pricing, or discussing sensitive deals. Here's how Katalyz handles security.

## Compliance

Katalyz's infrastructure and practices follow modern security and privacy best practices. For specific framework compliance (SOC 2, GDPR, HIPAA, regional regulations) or supporting agreements, please **contact us** with your scenario — we'll point you to the latest documentation available.

## Encryption

- **In transit** — all data moves over HTTPS with modern TLS (TLS 1.2+)
- **At rest** — all customer data is encrypted on disk using industry-standard algorithms (AES-256)
- **In backups** — backups are encrypted end-to-end

If someone intercepted data on the wire or physically accessed our storage, they'd only see encrypted content.

## Authentication

- **No passwords** — Katalyz uses magic-link authentication. There's no password for attackers to guess, phish, or steal.
- **Email-bound** — your access is tied to your email address; losing control of your email is the only credential-loss scenario
- **Short-lived tokens** — magic links expire after 48 hours
- **Multi-factor options** — on sensitive rooms, you may be asked for additional verification (email code)

## Signatures

Documents signed via Katalyz are:

- **Cryptographically sealed** — the completed PDF is digitally signed by our signing infrastructure
- **Tamper-evident** — any post-signing modification is detectable by any PDF reader
- **Retained** for the lifetime of the sender's account (and per legal retention requirements)

See [Legal validity of Katalyz signatures](→ 04-signatures/02-understanding-signatures/01-legal-validity) for details.

## Data residency

All Katalyz data is hosted in the **AWS Paris (eu-west-3)** region — regardless of your country. There's no separate per-region hosting for US or other customers.

## Access controls

On the sender's side:
- **Org roles** (Admin / Pro / Basic) limit who in their company can access your data
- **Room-specific roles** (Owner / Editor / Viewer) determine what each person can do
- **Participant removal** — the sender can remove anyone from a room, immediately revoking access

On Katalyz's side:
- **Principle of least privilege** — only staff with specific need can access customer data
- **Audit logs** — every access to customer data is logged
- **No bulk export** — our systems don't enable mass customer data export

## Incident response

If a security incident happens:
- We investigate immediately
- We notify affected customers promptly (within legal obligations)
- We document the root cause and remediation
- We publish a summary, where appropriate

## Your rights

You have standard data rights under GDPR:

- **Access** — request a copy of your data
- **Correction** — fix inaccurate data
- **Deletion** — request removal (subject to legal retention, e.g. signed contracts)
- **Portability** — get your data in a portable format
- **Objection** — object to certain processing

To exercise rights:
- **Start with the sender** — they control the room and are the primary data controller
- **Contact Katalyz directly** at **privacy@katalyz.co** if needed — especially for platform-level data

## Questions about security?

If you're evaluating Katalyz from a security or compliance perspective for your company:

- **Security questionnaires** — the sender can request our standard security documentation from us
- **Direct questions** — email **privacy@katalyz.co**

## Related articles
- [What Katalyz knows about you](https://katalyz.crisp.help/en/article/what-katalyz-knows-about-you-2lzu2f/)
- [Is my activity tracked?](https://katalyz.crisp.help/en/article/is-my-activity-tracked-1lcvdwe/)
- [Magic links explained](https://katalyz.crisp.help/en/article/magic-links-explained-1ppj2yb/)