Skip to main content
Security

Your batch records stay yours

Katalyze AI processes regulated pharmaceutical manufacturing data. We take data integrity and security as seriously as GMP requires.

ENCRYPTION AES-256 at rest TLS 1.3 in transit US East hosted (AWS) Encrypted key management ACCESS Role-based permissions SSO (SAML 2.0) optional Session timeout enforced MFA supported AUDIT TRAIL Every action timestamped Append-only log entries CSV / JSON export Human vs AI actions labeled DATA HANDLING Never used for AI training Full export on request Deletion within 30 days Contract + 30 day retention
Technical controls

Infrastructure and access security

Encryption at rest and in transit

All customer data encrypted with AES-256 at rest. All data in transit protected with TLS 1.3. Encryption keys managed separately from data storage with rotation policies in place.

US East infrastructure

Hosted on AWS us-east-1. All data processed and stored within the United States. No cross-border data transfer by default. Customers who require specific region constraints can discuss options during onboarding.

Role-based access controls

Configurable permission levels by role: reviewer, approver, administrator. SSO integration available via SAML 2.0. Session timeout enforcement. All authentication events logged with source IP and timestamp.

Immutable audit log

Every system event, user action, and AI operation is logged with millisecond timestamp and is append-only. Log entries cannot be modified or deleted. Logs are exportable in CSV and JSON for inspection readiness.

Vulnerability management

Automated dependency scanning integrated into the deployment pipeline. Security patches applied on a defined schedule. Internal penetration testing completed on pilot infrastructure; third-party engagement scheduled.

Secret and credential management

No secrets in code repositories. API keys and credentials managed through a secrets management system with access logging and rotation policies. Developer access to production data requires separate approval.

Data handling

What we do and do not do with your data

Your data is never used for AI training

Customer batch records, deviation reports, and quality data are processed solely to generate the review analysis and route results back to your team. They are never used to train, fine-tune, or improve our AI models. This is a hard contractual commitment, not a preference setting.

Retention and deletion

Data is retained for the duration of the customer contract plus 30 days. At contract end, all customer data is deleted from production systems within 30 days and from backup systems within the contractual window. Verified deletion receipts are available on request.

Full data export

You can export your complete data at any time during the contract: batch records, deviation histories, quality check logs, audit trail, all in standard formats. No exit penalty, no data lock-in.

0 customer data records used for AI model training
30d maximum data deletion window after contract end
Security roadmap

What we are working toward

SOC 2 Type II

Audit in planning, targeting completion in the first half of 2027. Will be published on this page when complete. We are not claiming a current certification that does not exist.

Penetration testing

Internal penetration test completed on pilot infrastructure. Third-party penetration test from an independent security firm is scheduled for the current year. Results will inform remediation priorities.

HIPAA-relevant controls

HIPAA-relevant controls are in place by design for manufacturers whose data may include patient-adjacent information. Not a HIPAA Business Associate Agreement by default; available on request for eligible customers.

Security questions specific to your regulatory environment: [email protected]
Questions

Have specific security requirements for regulated data?

We will walk through our controls in detail for your security review or vendor assessment process. Contact the team with your requirements and we will respond with specifics.