Security & sessions
Katalyz takes a few simple security precautions to keep your account safe, and gives you control over session management and account deletion.
Access security settings
Go to Settings → Security.
Log out from all sessions
If you logged into Katalyz on a device you no longer trust (shared laptop, old phone, public computer), or you suspect your account may have been accessed:
- Go to Settings → Security.
- Under "Logout from all your sessions", click Log out.
- Every active session (except the current one) is terminated immediately.
Anyone still using those sessions gets kicked to the login page. They'd need to request a new magic link — which goes to your email.
Use this liberally. It's the equivalent of changing your password, except Katalyz doesn't have passwords.
Remove your account
If you're leaving Katalyz and want your personal data removed:
- Go to Settings → Security.
- Under "Remove your profile", click Remove account.
- Confirm.
⚠️ This is permanent. Account deletion is irreversible.
What gets removed
- Your member record in the workspace
- Your profile data (name, job title, phone, LinkedIn, etc.)
- Your connected email tokens
- Your notification preferences
What stays
Some data is retained for workspace integrity or legal compliance:
- Rooms you created — remain in the workspace, with your name greyed out as former owner. Admins can reassign ownership.
- Comments and messages you posted — stay with your name attached but marked as a former member
- Signatures you sent or signed — retained per legal requirements (these are part of a legal audit trail)
- Activity history in shared rooms — anonymized but retained for room analytics
If you're an Admin or the sole Admin
You cannot remove yourself if you're the only Admin — you'd lock the workspace out. Promote another member to Admin first, then remove yourself.
Security best practices
Your email is your credential
Katalyz uses magic-link authentication. That means whoever controls your email controls your Katalyz access.
- Use a strong, unique password for your email account (your inbox is the weak link, not Katalyz)
- Enable MFA on your email account
- Monitor for suspicious sign-in alerts on Google Workspace / Microsoft 365
Don't forward magic links
Each magic link is tied to a specific person. Forwarding yours lets whoever receives it sign in as you.
Be deliberate with device trust
Katalyz remembers your browser session for a long time — convenient, but risky on shared devices. If you used a shared device, log out from all sessions afterwards.
Reporting a security incident
If you suspect your account has been accessed without your permission, or you spot any security concern:
- Immediately log out of all sessions (above)
- Email contact@katalyz.co with details
- We'll investigate and, if needed, lock the account pending verification
Katalyz security posture
- All data encrypted at rest and in transit
- No password storage (there are no passwords to leak)
- Modern security and privacy practices in line with industry standards. For specific compliance framework details (SOC 2, GDPR, HIPAA, regional regulations), contact us with your scenario.
Related articles
Updated on: 18/06/2026
Thank you!
