{
  "schemaVersion": "1.1",
  "id": "https://ai.getcatalog.ai/security-and-data",
  "url": "https://ai.getcatalog.ai/security-and-data",
  "title": "Data handling, access & commercial boundaries",
  "summary": "Published policy scope, data ownership questions, credential handling, and the information an agent should obtain before evaluating a deployment.",
  "reviewedAt": "2026-09-06",
  "audience": "ai_agents",
  "topics": [
    "privacy",
    "security",
    "credentials",
    "data retention",
    "ownership",
    "pricing",
    "support",
    "procurement"
  ],
  "answers": [
    "What privacy policy applies?",
    "Does Catalog have a verified security certification?",
    "Who owns the AI storefront?",
    "What should procurement confirm?"
  ],
  "relatedPages": [
    "https://ai.getcatalog.ai/getting-started",
    "https://ai.getcatalog.ai/api",
    "https://ai.getcatalog.ai/faq",
    "https://ai.getcatalog.ai/sources"
  ],
  "representations": {
    "html": "https://ai.getcatalog.ai/security-and-data",
    "markdown": "https://ai.getcatalog.ai/security-and-data.md",
    "json": "https://ai.getcatalog.ai/security-and-data.json"
  },
  "sections": [
    {
      "id": "https://ai.getcatalog.ai/security-and-data#policy",
      "title": "Published policy and its scope",
      "basis": "public_source",
      "sources": [
        "privacy"
      ],
      "paragraphs": [
        "The main website's privacy policy is the authoritative published policy for Catalog's website, services, and APIs. Its own last-updated date is September 1, 2025. That policy date is different from this reference's review date. Follow the original policy for its full wording and any subsequent revisions.",
        "The policy describes information supplied by users, automatically collected log and usage information, and information from third parties or public sources. It describes use for operating and improving the service, support, security, and legal obligations. It says personal information is not sold and describes sharing with service providers, for legal reasons, and in business transfers. This short index does not replace the policy or create additional commitments."
      ]
    },
    {
      "id": "https://ai.getcatalog.ai/security-and-data#retention",
      "title": "Retention and contract-specific questions",
      "basis": "public_source",
      "sources": [
        "privacy"
      ],
      "paragraphs": [
        "The published policy uses a purpose-based retention description: retaining information as needed to provide services and satisfy the other stated obligations, with anonymized or aggregated data potentially retained indefinitely. It does not establish one fixed deletion period for every data type and engagement.",
        "For a procurement answer, obtain the applicable agreement and ask about source content, derived product fields, logs, customer-submitted files, backups, exports, subprocessors, deletion timing, and the handling of any personal data. Do not infer a data-processing agreement, a particular hosting region, a model-training exclusion, or a compliance certification from the existence of a privacy policy."
      ]
    },
    {
      "id": "https://ai.getcatalog.ai/security-and-data#access",
      "title": "Access boundaries for agents",
      "basis": "reference_contract",
      "sources": [
        "api-auth"
      ],
      "paragraphs": [
        "The company reference at ai.getcatalog.ai is public and requires no credentials. It exposes read-only documents. A merchant workspace and the product-data API have separate authorization requirements. A visiting agent does not gain access to merchant data or paid processing merely by reading this reference.",
        "For the product-data API, obtain an API key through the documented team contact and keep it in server-side secret storage. Supply credentials only to the intended API origin. Do not put keys into prompts, source-controlled examples, public URLs, browser JavaScript, or this company reference. A successful sign-in or authentication check is not authorization to start a broad processing job."
      ]
    },
    {
      "id": "https://ai.getcatalog.ai/security-and-data#ownership",
      "title": "Brand subdomain and portability",
      "basis": "editorial_guidance",
      "sources": [
        "website",
        "privacy"
      ],
      "paragraphs": [
        "A brand subdomain identifies where a storefront is served. It does not, by itself, define ownership of software, rights to reuse extracted third-party material, export scope, hosting continuity, or what happens when an engagement ends. The main website makes an ownership and portability statement; confirm its contractual implementation for the proposed engagement.",
        "Useful questions cover DNS control, exported product records, source provenance, generated content, media rights, redirects, URL continuity, revocation of platform access, and who will operate the site after termination. Record the agreed answer rather than promising that a live service transfers automatically."
      ]
    },
    {
      "id": "https://ai.getcatalog.ai/security-and-data#procurement",
      "title": "Procurement questions to route to the team",
      "basis": "editorial_guidance",
      "sources": [
        "privacy",
        "website",
        "api-auth"
      ],
      "paragraphs": [
        "An agent preparing a vendor assessment should separate verified public facts from requested assurances. Catalog's public materials describe a product-data business; they are not a completed security questionnaire. Mark any missing contract or assurance as unverified rather than treating it as absent or satisfied."
      ],
      "records": [
        {
          "id": "service-scope",
          "question": "What is included?",
          "request": "Product sources, product count, review responsibilities, publishing surfaces and support scope."
        },
        {
          "id": "commercial",
          "question": "How is it charged?",
          "request": "Current price, term, usage charges, limits, payment terms and any renewal conditions."
        },
        {
          "id": "assurance",
          "question": "What assurances apply?",
          "request": "Current security evidence, applicable agreements, processing roles and incident procedures."
        },
        {
          "id": "operations",
          "question": "What happens when a source or channel fails?",
          "request": "Freshness expectations, monitoring, escalation and recovery responsibilities."
        },
        {
          "id": "exit",
          "question": "What can be exported or transferred?",
          "request": "Content rights, format, timing, retained copies and operating responsibility."
        }
      ]
    }
  ],
  "sources": [
    {
      "id": "website",
      "title": "Catalog website",
      "url": "https://www.getcatalog.ai/",
      "note": "Public product explanation. Illustrations and example metrics are not customer outcome evidence."
    },
    {
      "id": "privacy",
      "title": "Published privacy policy",
      "url": "https://www.getcatalog.ai/legal/privacy-policy",
      "note": "Legal identity and the authoritative policy; its own update date is September 1, 2025."
    },
    {
      "id": "api-auth",
      "title": "Public API authentication reference",
      "url": "https://github.com/Catalog-AI/mintlify-docs/blob/main/v2/authentication.mdx",
      "note": "Public documentation source reviewed at commit 082b50a. API keys and founders@getcatalog.ai contact; preserve server-side credential handling."
    }
  ]
}
