Your batch records stay yours
Katalyze AI processes regulated pharmaceutical manufacturing data. We take data integrity and security as seriously as GMP requires.
Infrastructure and access security
Encryption at rest and in transit
All customer data encrypted with AES-256 at rest. All data in transit protected with TLS 1.3. Encryption keys managed separately from data storage with rotation policies in place.
US East infrastructure
Hosted on AWS us-east-1. All data processed and stored within the United States. No cross-border data transfer by default. Customers who require specific region constraints can discuss options during onboarding.
Role-based access controls
Configurable permission levels by role: reviewer, approver, administrator. SSO integration available via SAML 2.0. Session timeout enforcement. All authentication events logged with source IP and timestamp.
Immutable audit log
Every system event, user action, and AI operation is logged with millisecond timestamp and is append-only. Log entries cannot be modified or deleted. Logs are exportable in CSV and JSON for inspection readiness.
Vulnerability management
Automated dependency scanning integrated into the deployment pipeline. Security patches applied on a defined schedule. Internal penetration testing completed on pilot infrastructure; third-party engagement scheduled.
Secret and credential management
No secrets in code repositories. API keys and credentials managed through a secrets management system with access logging and rotation policies. Developer access to production data requires separate approval.
What we do and do not do with your data
Your data is never used for AI training
Customer batch records, deviation reports, and quality data are processed solely to generate the review analysis and route results back to your team. They are never used to train, fine-tune, or improve our AI models. This is a hard contractual commitment, not a preference setting.
Retention and deletion
Data is retained for the duration of the customer contract plus 30 days. At contract end, all customer data is deleted from production systems within 30 days and from backup systems within the contractual window. Verified deletion receipts are available on request.
Full data export
You can export your complete data at any time during the contract: batch records, deviation histories, quality check logs, audit trail, all in standard formats. No exit penalty, no data lock-in.
What we are working toward
Audit in planning, targeting completion in the first half of 2027. Will be published on this page when complete. We are not claiming a current certification that does not exist.
Internal penetration test completed on pilot infrastructure. Third-party penetration test from an independent security firm is scheduled for the current year. Results will inform remediation priorities.
HIPAA-relevant controls are in place by design for manufacturers whose data may include patient-adjacent information. Not a HIPAA Business Associate Agreement by default; available on request for eligible customers.
Have specific security requirements for regulated data?
We will walk through our controls in detail for your security review or vendor assessment process. Contact the team with your requirements and we will respond with specifics.