Security · continuously monitored

Security you can verify.

Your data and privacy aren't a feature — they're the foundation. Catch is built on certified infrastructure, tested by outside experts, and transparent by default. We'll never sell your data, and we'll always tell you exactly how it's handled.

SOC 2 Type II infrastructure GDPR compliant CCPA compliant AES-256 at rest TLS 1.3 in transit Third-party pen tested DDoS-protected edge Google Cloud infra US data residency Anonymized analytics 24/7 monitoring Least-privilege access SOC 2 Type II infrastructure GDPR compliant CCPA compliant AES-256 at rest TLS 1.3 in transit Third-party pen tested DDoS-protected edge Google Cloud infra US data residency Anonymized analytics 24/7 monitoring Least-privilege access
0
Times we've sold your data
100%
Anonymized in analytics & BI
24/7
Infrastructure monitoring
256-bit
AES encryption at rest
// How we protect you

Security built in, not bolted on.

Three commitments hold the whole thing up — testing, policy, and transparency. None of them are optional.

01 / Testing

Independent penetration testing

The only way to know a system is hardened is to have someone try to break it. Our platform is regularly tested by independent North-American security firms, and remediating P0 findings is our highest priority — above shipping anything else.

02 / Policies

Industry-grade security policies

Security is a practice, not a checkbox. We operate documented policies for incident response, access control, backups, and disaster recovery — each with a named owner — and review them continuously as the product evolves.

03 / Transparency

Radical data transparency

We tell you exactly what we collect, where it lives, and who can touch it. Your data is anonymized in analytics and BI, and we will never sell or share it without your explicit consent. Not now, not ever.

// Under the hood

Hardened infrastructure.

We stand on certified providers so you don't have to take our word for it — you can read theirs.

Edge security

Traffic terminates on Google's global front end, with managed TLS and infrastructure-level DDoS protection.

Infrastructure security

US data residency

Data is hosted in the United States, encrypted in transit (TLS 1.3) and at rest (AES-256).

// Data privacy

Your data stays yours.

We follow the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR). In analytics, BI, and with any third-party vendor, your data — and your teammates' — is always anonymized.

We're all going to have to change how we think about data protection.
EDElizabeth DenhamFormer UK Information Commissioner
// Enterprise

Want the full picture?

We maintain a detailed catalogue of internal security policies that we share with enterprise customers on request.

Incident response Data retention Disaster recovery Backup policy Device management Access control