Security
What we do, and what we do not claim.
Security pages tend to imply more than they say. This one lists the controls that exist today and is explicit about the certifications Catalog AI does not hold.
Controls
What is in place today
- Organization isolation
- Every product, attribute set, job, and credit balance belongs to an organization. Access is checked against the organization on every request, and members of one cannot read another.
- Authentication
- Email and password, Google, and GitHub sign-in, with passkey support for existing accounts. Sessions are managed by Better Auth.
- Roles
- Members are invited with roles, and sensitive organization operations require owner or admin permission rather than mere membership.
- API keys
- Keys are scoped to an organization, carry their own configurable rate limit, and are individually revocable. Usage is tracked per key, so a compromised key is visible and containable.
- Payments
- Card details are handled by Stripe and never reach Catalog AI. We store the transaction record, not the instrument.
- Infrastructure
- Hosted on Google Cloud Platform, with object storage on Google Cloud Storage.
Being explicit
Three things worth stating outright
No published audit report
Catalog AI does not currently publish SOC 2 or ISO 27001. If that is a hard requirement for your organization, it is better that you know on this page than three calls in.
TDCCommerce is a separate scope
The Developer Company Inc. offers cybersecurity and compliance services and describes compliance frameworks elsewhere. Those statements cover that work, not automatically this product.
Your write path stays yours
Catalog AI does not push data into your storefront, PIM, or ERP. It exposes results and you decide what to write, which keeps the change under your own audit trail.
Data
Data handling
Is our catalog used to train models?
Your product data is processed to fulfil the jobs you run and stays scoped to your organization. It is not used to build a shared model across customers.
What data does Catalog AI actually hold?
The products, brands, categories, and attribute definitions you put in; the files you upload for AI Import; the results and sources of every job you run; and your account, organization, and credit records.
Where does the enrichment data come from?
Public web sources — product pages, manufacturer sites, identifier records — plus any documents you upload. Every enriched value carries the source it was read from, so the provenance is inspectable rather than assumed.
Can we delete our data?
Yes. Products, files, and organizations can be removed from the application. For a full account deletion, contact us and we will handle it.
Do you have SOC 2 or ISO 27001?
Catalog AI does not currently publish a SOC 2 or ISO 27001 report. If your procurement process requires one, talk to sales — we would rather tell you now than at the end of an evaluation.
Can you complete a security questionnaire?
Yes. Send it through the contact form marked as sales and we will work through it.
Full terms are in the privacy policy and terms of service. If something here is unclear or you need a specific commitment in writing, ask — a vague answer helps neither of us.
Send the questionnaire before the pilot, not after.
Sales can work through procurement paperwork in parallel with a technical trial.
5 credits on signup · no card required