Security

What we do, and what we do not claim.

Security pages tend to imply more than they say. This one lists the controls that exist today and is explicit about the certifications Catalog AI does not hold.

Controls

What is in place today

Organization isolation
Every product, attribute set, job, and credit balance belongs to an organization. Access is checked against the organization on every request, and members of one cannot read another.
Authentication
Email and password, Google, and GitHub sign-in, with passkey support for existing accounts. Sessions are managed by Better Auth.
Roles
Members are invited with roles, and sensitive organization operations require owner or admin permission rather than mere membership.
API keys
Keys are scoped to an organization, carry their own configurable rate limit, and are individually revocable. Usage is tracked per key, so a compromised key is visible and containable.
Payments
Card details are handled by Stripe and never reach Catalog AI. We store the transaction record, not the instrument.
Infrastructure
Hosted on Google Cloud Platform, with object storage on Google Cloud Storage.
Being explicit

Three things worth stating outright

No published audit report

Catalog AI does not currently publish SOC 2 or ISO 27001. If that is a hard requirement for your organization, it is better that you know on this page than three calls in.

TDCCommerce is a separate scope

The Developer Company Inc. offers cybersecurity and compliance services and describes compliance frameworks elsewhere. Those statements cover that work, not automatically this product.

Your write path stays yours

Catalog AI does not push data into your storefront, PIM, or ERP. It exposes results and you decide what to write, which keeps the change under your own audit trail.
Data

Data handling

Is our catalog used to train models?
Your product data is processed to fulfil the jobs you run and stays scoped to your organization. It is not used to build a shared model across customers.
What data does Catalog AI actually hold?
The products, brands, categories, and attribute definitions you put in; the files you upload for AI Import; the results and sources of every job you run; and your account, organization, and credit records.
Where does the enrichment data come from?
Public web sources — product pages, manufacturer sites, identifier records — plus any documents you upload. Every enriched value carries the source it was read from, so the provenance is inspectable rather than assumed.
Can we delete our data?
Yes. Products, files, and organizations can be removed from the application. For a full account deletion, contact us and we will handle it.
Do you have SOC 2 or ISO 27001?
Catalog AI does not currently publish a SOC 2 or ISO 27001 report. If your procurement process requires one, talk to sales — we would rather tell you now than at the end of an evaluation.
Can you complete a security questionnaire?
Yes. Send it through the contact form marked as sales and we will work through it.

Full terms are in the privacy policy and terms of service. If something here is unclear or you need a specific commitment in writing, ask — a vague answer helps neither of us.

Send the questionnaire before the pilot, not after.

Sales can work through procurement paperwork in parallel with a technical trial.

5 credits on signup · no card required