Security
How Catalyst keeps each client’s data separate, and what we commit to. Our commitments are written into the data processing agreement we sign with every client; more detail is shared with clients, and with prospective clients under NDA, on request.
What holds from day one
- We never sell, share or reuse a client’s data for anyone else, and never mix one client’s leads with another’s. Duplicates are matched only inside your own workspace.
- You can switch off our access at any time. On your word, we step out the same day.
- Providers that process your data are listed by category on the subprocessors page; clients receive the named list and advance notice of changes under the data processing agreement.
- Emails go out only through the pre-send gates: a signature, a postal address and an unsubscribe line; an address check before every email; one do-not-contact list for every engine; a daily and a rolling weekly sending cap; and one key that pauses outgoing email within seconds.
- Files are never attached to an email automatically, and a lead’s text is given to the model as data, with an instruction never to follow commands inside it.
With the platform
- Client isolation in the database itself. Every record is tied to your workspace, and the boundary between clients is enforced by the database, not only by the application.
- One controlled entry for automation. Every automated action is bound to the client it belongs to, never to what a request claims, and tests try to cross from one client to another.
- Encryption. Data is encrypted at rest and in transit.
- Location. Your database, sign-in and files are hosted in a European Union region, where the provider stores and primarily processes them under its data processing terms.
- Backups and erasure. Data is backed up automatically, and backups age out on a fixed schedule. When someone is erased, live data is deleted at once, and the erasure is applied again after any restore.
Certifications, honestly
We do not hold our own SOC 2 or ISO 27001 certification. With the platform, our database provider is independently audited (SOC 2 Type 2); its report is shared only under its own terms.
We do not promise “zero knowledge”: whoever processes data can technically see it. That is why our commitments are written into the data processing agreement we sign with every client.
Incidents
If a security incident affects your data, we notify you within the period set in the data processing agreement.