Articles on: Your profile

Security & sessions

Katalyz takes a few simple security precautions to keep your account safe, and gives you control over session management and account deletion.


Access security settings


Go to Settings → Security.


Log out from all sessions


If you logged into Katalyz on a device you no longer trust (shared laptop, old phone, public computer), or you suspect your account may have been accessed:


  1. Go to Settings → Security.
  2. Under "Logout from all your sessions", click Log out.
  3. Every active session (except the current one) is terminated immediately.


Anyone still using those sessions gets kicked to the login page. They'd need to request a new magic link — which goes to your email.


Use this liberally. It's the equivalent of changing your password, except Katalyz doesn't have passwords.


Remove your account


If you're leaving Katalyz and want your personal data removed:


  1. Go to Settings → Security.
  2. Under "Remove your profile", click Remove account.
  3. Confirm.


⚠️ This is permanent. Account deletion is irreversible.


What gets removed


  • Your member record in the workspace
  • Your profile data (name, job title, phone, LinkedIn, etc.)
  • Your connected email tokens
  • Your notification preferences


What stays


Some data is retained for workspace integrity or legal compliance:


  • Rooms you created — remain in the workspace, with your name greyed out as former owner. Admins can reassign ownership.
  • Comments and messages you posted — stay with your name attached but marked as a former member
  • Signatures you sent or signed — retained per legal requirements (these are part of a legal audit trail)
  • Activity history in shared rooms — anonymized but retained for room analytics


If you're an Admin or the sole Admin


You cannot remove yourself if you're the only Admin — you'd lock the workspace out. Promote another member to Admin first, then remove yourself.


Security best practices


Your email is your credential

Katalyz uses magic-link authentication. That means whoever controls your email controls your Katalyz access.


  • Use a strong, unique password for your email account (your inbox is the weak link, not Katalyz)
  • Enable MFA on your email account
  • Monitor for suspicious sign-in alerts on Google Workspace / Microsoft 365


Each magic link is tied to a specific person. Forwarding yours lets whoever receives it sign in as you.


Be deliberate with device trust

Katalyz remembers your browser session for a long time — convenient, but risky on shared devices. If you used a shared device, log out from all sessions afterwards.


Reporting a security incident


If you suspect your account has been accessed without your permission, or you spot any security concern:


  1. Immediately log out of all sessions (above)
  2. Email contact@katalyz.co with details
  3. We'll investigate and, if needed, lock the account pending verification


Katalyz security posture


  • All data encrypted at rest and in transit
  • No password storage (there are no passwords to leak)
  • Modern security and privacy practices in line with industry standards. For specific compliance framework details (SOC 2, GDPR, HIPAA, regional regulations), contact us with your scenario.


Updated on: 18/06/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!