Qatalyst handles client records, time and expense entries, and invoices — data that has to be trustworthy, not just convenient. Here's how we treat it.
Every password is hashed before it's saved. Even in the extremely unlikely event of a database compromise, your actual password is never recoverable from it.
Beyond your password, you can add an authenticator app code, an emailed one-time code, or a passkey — whichever fits how you work. All are optional, and yours to enable per account.
Clients you invite into their portal get a secure, single-use access link — never a password to remember or a login you have to manage for them. You can revoke or regenerate that link at any time.
Your workspace's data is scoped strictly to your organization, and role-based permissions (Owner, Admin, Manager, Member) govern exactly who inside it can see or change what.
Every connection to Qatalyst — your dashboard, your client's portal, everything — is encrypted end to end over HTTPS.
Invoices, receipts, and documents are stored directly in our access-controlled database rather than a generic public file-sharing service.
We're happy to answer it directly — email us at hello@qatalyst.io.