Enterprise-grade trust for regulated science
SOC 2 Type II across four Trust Services Criteria. Built for GxP environments. Supports FDA 21 CFR Part 11 and EU Annex 11 requirements for electronic records. Deployed in your own cloud.
Compliance & Certifications
- SOC 2 Type IILast audited February 2026
- Independently examined by GreenHat Assurance LLC, covering four AICPA Trust Services Criteria: Security, Availability, Confidentiality, and Privacy. Report available on request under NDA.
- GxPBuilt for GxP environments
- Designed to support validated GxP processes. Controls span audit trail capture, access control, segregation of duties, and source traceability. Supplier documentation available for your validation.
- FDA 21 CFR Part 11 & EU Annex 11Supports electronic records requirements
- Tamper-evident audit trails with an independent chain verifier and seven-year retention. Role-scoped audit visibility. Segregation of duties enforced on approval routes. Access denials recorded alongside approvals. Electronic signatures are planned.
- ALCOA+Supported across the record
- Every action attributable to a person or agent principal and recorded as it happens. Outputs linked to their original source rather than replacing it. Corrections and rejections retained in the same tamper-evident chain.
- Data Protection: GDPR and PIPEDAProcessor role · DPA available
- Katalyze acts as processor; you remain the controller and owner of your data. A Data Processing Agreement is executed as part of standard diligence. Personal information handled through our Canadian operations is managed in line with PIPEDA's principles. Because deployment runs inside your own cloud environment, data residency follows your configuration.
- HIPAASecurity Rule safeguards supported
- Where protected health information is in scope, Katalyze's access controls, tamper-evident audit trail, encryption, and personnel controls are designed to support HIPAA Security Rule safeguards. Talk to us early if PHI forms part of your deployment.
- ISO/IEC 27001:2022Certification is planned
- We are working toward ISO/IEC 27001:2022 certification of our Information Security Management System. Many of the underlying controls are already examined under our SOC 2 Type II report and available for review today.
Validation is shared work, and we're specific about the collaboration
Validation is assessed against your intended use, in your environment, by your Quality unit. What a supplier can do is carry its share of the evidence and be clear about where the line falls.
What you own
- Intended use and user requirements.
- Risk classification and software categorization under GAMP 5.
- Your validation plan.
- Qualification in your environment.
- Acceptance of results.
- Periodic review.
What Katalyze provides
- Architecture and data-flow documentation.
- Secure development lifecycle and change control processes.
- Testing and release evidence.
- Access control and audit trail design.
- Our SOC 2 Type II report.
- Supplier documentation aligned to GAMP 5 expectations for supplier-provided evidence.
- Advance notice of material changes affecting validated functionality, with impact assessment.
Scope is agreed per engagement, so your Quality unit gets the evidence your risk assessment actually calls for rather than a generic pack.
Change control. Material changes affecting validated functionality come with written notice, release notes, and a documented impact assessment, so revalidation scope is known before a change lands rather than discovered after it.
Data Security
- 01EncryptionCustomer data encrypted in transit and at rest. Encryption and restricted IAM policies defined in infrastructure-as-code and reviewed through change control.
- 02Vulnerability ManagementContinuous scanning across cloud services and third-party dependencies. Findings rated by CVSS severity and remediated on defined timelines, with critical treated as CVSS 9.0 or above.
- 03Secure DevelopmentSource code reviewed before every production release. Development, test, and production environments segregated. Automated security scanning in CI on infrastructure changes. Regular dependency and container patching.
- 04Backups & RecoveryDaily encrypted backups stored redundantly. Monthly integrity testing. Documented restore procedures.
- 05Incident ResponseDocumented incident response process with contractual notification commitments for material incidents involving customer data.
Access Control & Authentication
Katalyze supports enterprise single sign-on with organization-scoped access control, evaluated at a central policy enforcement point.
- 01Single sign-on (SSO)Enterprise identity providers supported via OIDC, configured per organization.
- 02Role-based access control (RBAC)Permissions scoped by organization and workspace.
- 03Policy enforcementEvery access decision, including denials, evaluated centrally and written to the audit trail.
- 04Audit loggingAuthentication and data access events logged and viewable in an in-product audit console.
Your data stays in your environment and under your control
Katalyze runs model inference through AWS Bedrock inside your own cloud account. Agents operate under the same access controls as the people who invoke them, and every run is recorded.
- 01Human decision authorityAgents assemble evidence, investigate, and draft. Your qualified reviewers decide and sign. Outputs carrying regulatory weight route to a human approver, with segregation of duties enforced between producer and approver. Katalyze does not approve a batch, close a deviation, or release a product.
- 02Data isolationYour data is not used to train or improve general-purpose AI models.
- 03Scoped executionAgents run under scoped authority through the same policy enforcement point as human users. An agent cannot access what its requester cannot access, and agent principals are bound to their workspace.
- 04Source-grounded resultsEvery output links back to the record it came from. Missing or uncertain information is surfaced for expert review rather than resolved silently.
- 05Governed releasesAgent, prompt, and skill versions are captured with each run. Agents are evaluated against fixed, human-labeled ground-truth datasets and a simulated manufacturing environment, tracked across versions.
Deployment
For pharma customers whose security posture rules out shared SaaS, Katalyze deploys into your own cloud environment. Client data remains on client-controlled infrastructure.
- 01Customer-managed cloudDeployed in your AWS account on Kubernetes (EKS), alongside Snowflake where you run it.
- 02Data residencyResidency follows your cloud configuration and region. Data does not leave your boundary.
- 03Your identity and networkRuns under your IAM, inside your network controls, against your identity provider.
- 04Pre-deployment discoveryAuthentication, network, and AI provider requirements are scoped and answered before a deployment date is agreed.
- 05Connected without migrationKatalyze connects to the systems you already run. Your systems remain the source of truth.
Personnel Security
- 01Background checks conducted for all new hires.Confidentiality agreements signed at onboarding.
- 02Recurring security awareness training for all staff.
- 03All employee devices managed and encrypted, with endpoint detection and response.Least-privilege access to source code and customer data, with multi-factor authentication required for privileged access.
- 04Vendor and subprocessor risk review.
- Have security questions?
- security@katalyzeai.com
- Request the SOC 2 reportAvailable under NDA
- security@katalyzeai.com
- Responsible disclosureReport a vulnerability
- security@katalyzeai.com
