Security & compliance
Encrypted before it leaves your device.
We designed CattStack so that a subpoena, a rogue employee, or a full server breach all reveal the same thing about your files: nothing.
Zero-knowledge by construction
When you create a vault, your passphrase is stretched with Argon2id into a master key that never leaves your machine. Each file gets a random content key sealed with that master key. We store only ciphertext and wrapped keys — we cannot read your files, and we cannot reset your passphrase for you.
AES-256GCM per-file content encryption
Argon2idmemory-hard key derivation
X25519key exchange for sharing
Where your data lives
- Primary storage in ISO 27001-certified facilities in Reykjavík (IS) and Helsinki (FI).
- Region pinning: choose EU or leave the default, and your ciphertext never leaves it.
- Encrypted, geo-redundant backups with an 11-nines durability target.
How we operate
- Annual third-party penetration tests; summaries available under NDA.
- SSO/SAML and SCIM provisioning on the Business plan.
- Signed release builds and reproducible desktop clients.
- GDPR data-processing agreement available to every paid customer.
Responsible disclosure
Found something? Email security@catttkak.homes with steps to reproduce. We acknowledge reports within two business days and run a paid bounty for qualifying issues.