Articles on: For room visitors

How we protect your data

Your data deserves serious protection — especially when you're signing contracts, sharing pricing, or discussing sensitive deals. Here's how Katalyz handles security.


Compliance


Katalyz's infrastructure and practices follow modern security and privacy best practices. For specific framework compliance (SOC 2, GDPR, HIPAA, regional regulations) or supporting agreements, please contact us with your scenario — we'll point you to the latest documentation available.


Encryption


  • In transit — all data moves over HTTPS with modern TLS (TLS 1.2+)
  • At rest — all customer data is encrypted on disk using industry-standard algorithms (AES-256)
  • In backups — backups are encrypted end-to-end


If someone intercepted data on the wire or physically accessed our storage, they'd only see encrypted content.


Authentication


  • No passwords — Katalyz uses magic-link authentication. There's no password for attackers to guess, phish, or steal.
  • Email-bound — your access is tied to your email address; losing control of your email is the only credential-loss scenario
  • Short-lived tokens — magic links expire after 48 hours
  • Multi-factor options — on sensitive rooms, you may be asked for additional verification (email code)


Signatures


Documents signed via Katalyz are:


  • Cryptographically sealed — the completed PDF is digitally signed by our signing infrastructure
  • Tamper-evident — any post-signing modification is detectable by any PDF reader
  • Retained for the lifetime of the sender's account (and per legal retention requirements)


See [Legal validity of Katalyz signatures](→ 04-signatures/02-understanding-signatures/01-legal-validity) for details.


Data residency


All Katalyz data is hosted in the AWS Paris (eu-west-3) region — regardless of your country. There's no separate per-region hosting for US or other customers.


Access controls


On the sender's side:

  • Org roles (Admin / Pro / Basic) limit who in their company can access your data
  • Room-specific roles (Owner / Editor / Viewer) determine what each person can do
  • Participant removal — the sender can remove anyone from a room, immediately revoking access


On Katalyz's side:

  • Principle of least privilege — only staff with specific need can access customer data
  • Audit logs — every access to customer data is logged
  • No bulk export — our systems don't enable mass customer data export


Incident response


If a security incident happens:

  • We investigate immediately
  • We notify affected customers promptly (within legal obligations)
  • We document the root cause and remediation
  • We publish a summary, where appropriate


Your rights


You have standard data rights under GDPR:


  • Access — request a copy of your data
  • Correction — fix inaccurate data
  • Deletion — request removal (subject to legal retention, e.g. signed contracts)
  • Portability — get your data in a portable format
  • Objection — object to certain processing


To exercise rights:

  • Start with the sender — they control the room and are the primary data controller
  • Contact Katalyz directly at privacy@katalyz.co if needed — especially for platform-level data


Questions about security?


If you're evaluating Katalyz from a security or compliance perspective for your company:


  • Security questionnaires — the sender can request our standard security documentation from us
  • Direct questions — email privacy@katalyz.co


Updated on: 18/06/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!