> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://katalyz.crisp.help/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Security & sessions

Katalyz takes a few simple security precautions to keep your account safe, and gives you control over session management and account deletion.

## Access security settings

Go to **Settings → Security**.

## Log out from all sessions

If you logged into Katalyz on a device you no longer trust (shared laptop, old phone, public computer), or you suspect your account may have been accessed:

1. Go to **Settings → Security**.
2. Under **"Logout from all your sessions"**, click **Log out**.
3. Every active session (except the current one) is terminated immediately.

Anyone still using those sessions gets kicked to the login page. They'd need to request a new magic link — which goes to your email.

Use this liberally. It's the equivalent of changing your password, except Katalyz doesn't have passwords.

## Remove your account

If you're leaving Katalyz and want your personal data removed:

1. Go to **Settings → Security**.
2. Under **"Remove your profile"**, click **Remove account**.
3. Confirm.

⚠️ **This is permanent.** Account deletion is irreversible.

### What gets removed

- Your member record in the workspace
- Your profile data (name, job title, phone, LinkedIn, etc.)
- Your connected email tokens
- Your notification preferences

### What stays

Some data is retained for workspace integrity or legal compliance:

- **Rooms you created** — remain in the workspace, with your name greyed out as former owner. Admins can reassign ownership.
- **Comments and messages** you posted — stay with your name attached but marked as a former member
- **Signatures you sent or signed** — retained per legal requirements (these are part of a legal audit trail)
- **Activity history in shared rooms** — anonymized but retained for room analytics

### If you're an Admin or the sole Admin

You cannot remove yourself if you're the only Admin — you'd lock the workspace out. Promote another member to Admin first, then remove yourself.

## Security best practices

### Your email is your credential
Katalyz uses magic-link authentication. That means **whoever controls your email controls your Katalyz access.**

- **Use a strong, unique password** for your email account (your inbox is the weak link, not Katalyz)
- **Enable MFA** on your email account
- **Monitor for suspicious sign-in alerts** on Google Workspace / Microsoft 365

### Don't forward magic links
Each magic link is tied to a specific person. Forwarding yours lets whoever receives it sign in as you.

### Be deliberate with device trust
Katalyz remembers your browser session for a long time — convenient, but risky on shared devices. If you used a shared device, **log out from all sessions** afterwards.

## Reporting a security incident

If you suspect your account has been accessed without your permission, or you spot any security concern:

1. **Immediately** log out of all sessions (above)
2. **Email contact@katalyz.co** with details
3. We'll investigate and, if needed, lock the account pending verification

## Katalyz security posture

- **All data encrypted** at rest and in transit
- **No password storage** (there are no passwords to leak)
- Modern security and privacy practices in line with industry standards. For specific compliance framework details (SOC 2, GDPR, HIPAA, regional regulations), **contact us** with your scenario.

## Related articles
- [Logging in with a magic link](https://katalyz.crisp.help/en/article/logging-in-with-a-magic-link-t42xpj/)
- [Your personal profile](https://katalyz.crisp.help/en/article/your-personal-profile-txq1jv/)
- [Magic links explained](https://katalyz.crisp.help/en/article/magic-links-explained-1ppj2yb/)