Security & compliance

Encrypted before it leaves your device.

We designed CattStack so that a subpoena, a rogue employee, or a full server breach all reveal the same thing about your files: nothing.

Zero-knowledge by construction

When you create a vault, your passphrase is stretched with Argon2id into a master key that never leaves your machine. Each file gets a random content key sealed with that master key. We store only ciphertext and wrapped keys — we cannot read your files, and we cannot reset your passphrase for you.

AES-256GCM per-file content encryption
Argon2idmemory-hard key derivation
X25519key exchange for sharing

Where your data lives

  • Primary storage in ISO 27001-certified facilities in Reykjavík (IS) and Helsinki (FI).
  • Region pinning: choose EU or leave the default, and your ciphertext never leaves it.
  • Encrypted, geo-redundant backups with an 11-nines durability target.
Map of CattStack data regions in Reykjavik and Helsinki
Your ciphertext is pinned to the EU region you choose.

How we operate

  • Annual third-party penetration tests; summaries available under NDA.
  • SSO/SAML and SCIM provisioning on the Business plan.
  • Signed release builds and reproducible desktop clients.
  • GDPR data-processing agreement available to every paid customer.

Responsible disclosure

Found something? Email security@catttkak.homes with steps to reproduce. We acknowledge reports within two business days and run a paid bounty for qualifying issues.