Security

How Catalyst keeps each client’s data separate, and what we commit to. Our commitments are written into the data processing agreement we sign with every client; more detail is shared with clients, and with prospective clients under NDA, on request.

Last updated 13 September 2026

What holds from day one

  • We never sell, share or reuse a client’s data for anyone else, and never mix one client’s leads with another’s. Duplicates are matched only inside your own workspace.
  • You can switch off our access at any time. On your word, we step out the same day.
  • Providers that process your data are listed by category on the subprocessors page; clients receive the named list and advance notice of changes under the data processing agreement.
  • Emails go out only through the pre-send gates: a signature, a postal address and an unsubscribe line; an address check before every email; one do-not-contact list for every engine; a daily and a rolling weekly sending cap; and one key that pauses outgoing email within seconds.
  • Files are never attached to an email automatically, and a lead’s text is given to the model as data, with an instruction never to follow commands inside it.

With the platform

  • Client isolation in the database itself. Every record is tied to your workspace, and the boundary between clients is enforced by the database, not only by the application.
  • One controlled entry for automation. Every automated action is bound to the client it belongs to, never to what a request claims, and tests try to cross from one client to another.
  • Encryption. Data is encrypted at rest and in transit.
  • Location. Your database, sign-in and files are hosted in a European Union region, where the provider stores and primarily processes them under its data processing terms.
  • Backups and erasure. Data is backed up automatically, and backups age out on a fixed schedule. When someone is erased, live data is deleted at once, and the erasure is applied again after any restore.

Certifications, honestly

We do not hold our own SOC 2 or ISO 27001 certification. With the platform, our database provider is independently audited (SOC 2 Type 2); its report is shared only under its own terms.

We do not promise “zero knowledge”: whoever processes data can technically see it. That is why our commitments are written into the data processing agreement we sign with every client.

Incidents

If a security incident affects your data, we notify you within the period set in the data processing agreement.