Your data stays yours.
Built for the teams that hold the organisation to a higher standard — so it clears that bar itself.
Three commitments, by design.
A system that helps you manage risk has to be exemplary on security itself. Three principles are wired into how Catalsy works.
Need-to-know access
Answers respect your existing permissions — information surfaced strictly on a need-to-know basis.
Data protection
Enterprise-grade security. Your data is never used to train foundation models.
Full auditability
Every question, answer, routing decision and piece of AI reasoning — logged.
Where we are, honestly.
We'd rather tell you exactly where we stand than imply more than we've earned.
Standards we hold ourselves to
We're building Catalsy to enterprise security standards from day one. SOC 2 Type II is in progress, and our controls, policies and sub-processor governance are designed against it as we go.
We'd rather tell you exactly where we are than imply more than we've earned — design partners get our current security documentation on request.
Where your data lives
Catalsy runs on established, security-certified cloud infrastructure, with EU data residency available for customers who need it. We keep a current list of sub-processors and the data each one touches, and we notify customers before it changes.
Your data is encrypted in transit and at rest, segregated per customer, and never used to train foundation models.
Watching for risk, without watching your people.
Catalsy exists to help people do the right thing. A product with that mission has to be exemplary on privacy itself — not as a checkbox, but as a matter of principle. Here is how we think, and what we will and won't do.
These principles are our commitment to how we build — distinct from our legal Privacy Notice, which is the formal document covering how we process personal data.
Metadata over content
We work from the patterns and signals around how work happens — who is doing what, where, and how data moves — not by reading the contents of your people's messages and documents. The goal is to understand risk, not to surveil individuals.
Minimal by default
We look at the least we need to assess a risk, and no more. Less data is not a limitation — it's the design.
Need-to-know, always
Insights and answers respect your existing permission settings. Nothing surfaces to people who shouldn't see it.
Your data stays yours
It is never sold, and never used to train foundation models. You remain in control of your information at all times.
Transparent & auditable
Every assessment, action and piece of AI reasoning is logged and reviewable. You can always see what happened and why.
Humans stay in control
Catalsy assists, recommends and drafts. The decisions that carry weight stay with your people.
What this means in practice.
We'd rather catch less and stay trusted than catch everything and become the risk. Where we have to choose between more visibility and more privacy, we design for privacy first and earn visibility through transparency.
As the product develops, these principles are the constraints we build inside — and the standard we invite our customers to hold us to.
Hold us to this.
Design partners get our current security documentation on request. Come see how Catalsy handles your data.
Get early access










