Trust Center

Enterprise-Grade Security & Privacy by Default

How Katalyst protects voice streams, customer transcripts, and merchant payment systems with bank-grade infrastructure.

  • SOC 2 Type II aligned infrastructure
  • PCI-DSS Level 1 zero-scope architecture
  • HIPAA readiness profile
  • TLS 1.3 & AES-256 encrypted
Compliance program

How your data is protected

Four controls do most of the work, and every one of them is on before you take your first call.

Encrypted at every hop

Live call audio travels over WebRTC with DTLS key exchange and SRTP media encryption. Every web and API request uses TLS 1.3, and stored audio and transcripts sit behind AES-256 encryption at rest.

Multi-tenant data isolation

Every table enforces PostgreSQL row-level security scoped to the owning workspace. A query from one store physically cannot return another store's orders, recordings, transcripts or staff records — including AI knowledge lookups.

Zero-scope PCI payments

Agents never take a card number by voice or text. They send a secure payment link instead, so card data never enters a phone line, a transcript or a recording. Card-like sequences are stripped before anything is written down.

Ephemeral data lifecycle

You choose how long recordings and transcripts live: 30, 60, 90 days, a year, or forever. A nightly job permanently deletes the audio files and wipes the text once the window closes, and writes the purge to your audit trail.

Need the paperwork for your security review?

Request the security and architecture overview, or ask for a standard Business Associate Agreement if you operate in healthcare or legal services.