Security & data protection
Your catalog holds commercially sensitive data: unreleased products, pricing logic, supplier terms, regulated claims, and channel-specific copy. CataZenta is built so security is part of the platform architecture — not a checklist added after the product was designed.
This page is for security, IT, and procurement teams evaluating CataZenta, and for brand leaders who need confidence before they centralize product truth in one system.
Why security matters in product operations
| Risk without governance | What breaks |
|---|---|
| Catalog data in spreadsheets and email | No single audit trail; version chaos before launch |
| Shared logins to marketplace tools | No role separation; anyone can publish |
| Public AI tools on raw exports | Data leaves your boundary; no permission model |
| Legacy PIM with weak access control | Syndication mistakes; cross-brand leakage in groups |
CataZenta addresses these by combining workspace isolation, role-based access, encrypted integrations, and human approval before content goes live on channels.
How CataZenta approaches security
Where CataZenta wins vs common alternatives
| Capability | Spreadsheets & files | Generic AI chat | CataZenta |
|---|---|---|---|
| Who can see which brand’s data | Manual folder discipline | N/A — paste risk | Workspace isolation on every feature |
| Who can publish to Amazon/Shopify | Unclear | N/A | Permissions + optional approval workflows |
| Audit trail for changes | File versions only | Opaque | Product, workflow, and integration activity |
| AI on live catalog | Export + upload | Outside your controls | Zen AI & MCP on your data, your roles |
| Marketplace credentials | Shared passwords | N/A | Encrypted storage; not exposed in routine APIs |
| Enterprise review | Ad hoc | Vendor policies vary | Security pack, DPA, architecture review on request |
CataZenta is strongest when you need one governed catalog that feeds people, channels, and AI agents — without treating security as a separate project.
Your data stays in your workspace
Workspace (tenant) isolation
CataZenta separates customers at the organization and workspace (tenant) level. A user working in Brand A’s workspace cannot browse Brand B’s products, assets, export history, or AI context — including when using Zen AI or MCP agents.
This matters for:
- Multi-brand groups — one group, many labels, strict boundaries
- Regional splits — EU vs US catalogs with different compliance needs
- Sandbox workspaces — integrators and agencies test without touching production data
→ Multi-tenant design · Core concepts
Encryption and transport
- HTTPS/TLS for all hosted API and application traffic
- Encryption at rest for platform data stores in cloud infrastructure
- No return of raw secrets in standard listing APIs for marketplace connections
Product and media data
- Catalog content, DAM assets, and syndication history belong to your workspace
- Media access follows the same permission model as catalog APIs
- Export snapshots and job results are tied to your tenant scope
Access control people actually use
Sign-in and tokens
Users and automation authenticate with industry-standard signed tokens (asymmetric signing). Only the identity service can issue tokens; all other components verify them. That limits blast radius if a single service were ever compromised.
Roles and permissions
Permissions are enforced on every API request — the web UI reflects the same rules, but the API is the source of truth. Typical enterprise patterns:
| Role pattern | Usually can |
|---|---|
| Merchandising | Edit products, run enrichment, cannot approve publish |
| Syndication | Manage connections, export jobs, channel mappings |
| Brand / legal | Approve workflows, read-only on sensitive attributes |
| Read-only / audit | View catalog and reports, no writes |
Fine-grained entitlements align to product areas (PIM, DAM, syndication, AI, Brand Hub) so you do not give everyone full admin access.
Automation and MCP
- Service accounts and API keys are for integrations and scripts — scoped like human users
- MCP tools (Claude, ChatGPT, Cursor, etc.) execute with your identity and permissions, not a shared super-user
- Destructive or publish actions are explicit tool calls — auditable, not hidden prompts
→ API authentication · Service account recipe · MCP authentication
AI without losing control
AI is powerful only when it respects the same boundaries as your team.
| Principle | What it means for you |
|---|---|
| Tenant-scoped context | Models work on your catalog in your workspace — not a communal pool of customer data |
| Permissions apply | Users only see and change what their role allows — in Zen AI and in MCP |
| Review before live | AI proposes; workflows and approvals gate what reaches channels |
| Bring your own keys (optional) | Tenants can use provider credentials under your AI governance policies |
| Usage visibility | AI activity and usage can be monitored per workspace |
CataZenta is not a generic chatbot on exported CSVs. Structured families and attributes make AI safer and more accurate because the model reads governed fields, not free text in random columns.
Integrations and credentials
Connecting Amazon, Shopify, or ERP systems requires secrets. CataZenta:
- Stores connector credentials encrypted
- Avoids echoing secrets back in normal API responses
- Scopes import/export jobs to your workspace
- Supports webhooks and API access with the same authentication model
Syndication mistakes are reduced with completeness checks, validation rules, and per-SKU job results before you assume a listing is live.
Auditability and compliance readiness
Operational audit
- Workflows and tasks — who approved what, and when
- Task history — status changes and assignments over time
- Catalog changes — tied to authenticated users
- Export/import jobs — per-item success and failure for accountability
Enterprise procurement
We support structured security reviews as part of enterprise onboarding:
| Deliverable | Typical use |
|---|---|
| Security questionnaire | Vendor risk assessment |
| Data processing agreement (DPA) | GDPR / privacy legal review |
| Architecture overview | IT security workshop |
| Penetration test summary | When available for your tier / timeline |
Contact your CataZenta account team or request a demo to start a review. A public trust center with policies and status pages is on the roadmap — ask for the latest pack today.
Specific certifications (e.g. SOC 2, ISO 27001) vary by deployment and roadmap. Your account team will share current posture and timelines — we do not list certificates here that are not yet in force for your contract.
Infrastructure trust (hosted platform)
CataZenta’s hosted environment is built on AWS with infrastructure defined as code. Practices include:
- Private networking between application tiers and data stores
- Secrets management for database and signing material — not committed to source repositories
- TLS termination at the edge for customer traffic
- Monitoring and alerting for operational incidents
- Separation of production from non-production environments
Details for your security review are provided in the enterprise security pack (network diagrams, data flows, subprocessors).
Shared responsibility
Security is a partnership. CataZenta is responsible for platform controls, patching, and hosted infrastructure. You are responsible for:
- Assigning appropriate roles to users and partners
- Rotating API keys when staff or agencies change
- Configuring workflows for regulated or high-risk attributes
- Reviewing AI suggestions before publish when your policy requires it
- Classifying which data you place in the PIM (personal data minimization)
We provide the controls; your operating model determines how strong day-to-day practice is.
Security checklist for evaluators
Use this when comparing vendors:
- Isolation — Can one brand’s users or agents access another brand’s catalog? (In CataZenta: no, within tenant boundaries.)
- Authorization — Are restrictions enforced on APIs, not only in the UI? (Yes.)
- AI data handling — Is catalog data sent to AI within tenant scope and policy? (Yes — with optional BYOK.)
- Credentials — How are marketplace tokens stored? (Encrypted; not returned in list APIs.)
- Audit — Can you show who published SKU X and who approved it? (Workflows, jobs, and identity context.)
- Review materials — Can the vendor support DPA and security questionnaire? (Yes — on request.)
Related documentation
| Topic | Link |
|---|---|
| Workspace model | Multi-tenant design |
| Authentication | API authentication |
| Architecture overview | Architecture |
| Brand governance | How brands win |
| Catalog setup | Catalog fundamentals |
Questions for security review? Book a demo and ask for the security & compliance pack.