How we protect your data
Your data deserves serious protection — especially when you're signing contracts, sharing pricing, or discussing sensitive deals. Here's how Katalyz handles security.
Compliance
Katalyz's infrastructure and practices follow modern security and privacy best practices. For specific framework compliance (SOC 2, GDPR, HIPAA, regional regulations) or supporting agreements, please contact us with your scenario — we'll point you to the latest documentation available.
Encryption
- In transit — all data moves over HTTPS with modern TLS (TLS 1.2+)
- At rest — all customer data is encrypted on disk using industry-standard algorithms (AES-256)
- In backups — backups are encrypted end-to-end
If someone intercepted data on the wire or physically accessed our storage, they'd only see encrypted content.
Authentication
- No passwords — Katalyz uses magic-link authentication. There's no password for attackers to guess, phish, or steal.
- Email-bound — your access is tied to your email address; losing control of your email is the only credential-loss scenario
- Short-lived tokens — magic links expire after 48 hours
- Multi-factor options — on sensitive rooms, you may be asked for additional verification (email code)
Signatures
Documents signed via Katalyz are:
- Cryptographically sealed — the completed PDF is digitally signed by our signing infrastructure
- Tamper-evident — any post-signing modification is detectable by any PDF reader
- Retained for the lifetime of the sender's account (and per legal retention requirements)
See [Legal validity of Katalyz signatures](→ 04-signatures/02-understanding-signatures/01-legal-validity) for details.
Data residency
All Katalyz data is hosted in the AWS Paris (eu-west-3) region — regardless of your country. There's no separate per-region hosting for US or other customers.
Access controls
On the sender's side:
- Org roles (Admin / Pro / Basic) limit who in their company can access your data
- Room-specific roles (Owner / Editor / Viewer) determine what each person can do
- Participant removal — the sender can remove anyone from a room, immediately revoking access
On Katalyz's side:
- Principle of least privilege — only staff with specific need can access customer data
- Audit logs — every access to customer data is logged
- No bulk export — our systems don't enable mass customer data export
Incident response
If a security incident happens:
- We investigate immediately
- We notify affected customers promptly (within legal obligations)
- We document the root cause and remediation
- We publish a summary, where appropriate
Your rights
You have standard data rights under GDPR:
- Access — request a copy of your data
- Correction — fix inaccurate data
- Deletion — request removal (subject to legal retention, e.g. signed contracts)
- Portability — get your data in a portable format
- Objection — object to certain processing
To exercise rights:
- Start with the sender — they control the room and are the primary data controller
- Contact Katalyz directly at privacy@katalyz.co if needed — especially for platform-level data
Questions about security?
If you're evaluating Katalyz from a security or compliance perspective for your company:
- Security questionnaires — the sender can request our standard security documentation from us
- Direct questions — email privacy@katalyz.co
Related articles
Updated on: 18/06/2026
Thank you!
