Catchment | Security & Legal
Security & Legal

Built to hold data that gets audited.

Catchment holds reporting that ends up in front of clients, auditors and boards. Here is how that data is protected, and the documents that govern the platform.

Security

How project data is protected.

Encryption

Data is encrypted in transit and at rest. Access to production systems is restricted and logged.

Data residency

Customer data is hosted in Australia. It is not sold, shared or used for anything other than delivering the platform.

Access control

Every user sees only the projects and packages that belong to them. Permissions are role-based and set per project.

Audit trail

Submissions, edits and certifications are timestamped against the user who made them, so every figure traces to a person and a document.

Backups and continuity

Data is backed up on a regular schedule, with recovery procedures tested so reporting history is never lost.

Responsible disclosure

Found a vulnerability? Report it to legal@catchment.software and we will respond promptly.

Legal

The documents that govern the platform.

Privacy Policy

What personal information we collect, why, and how it is handled.

Read the policy →

Terms & Conditions

The agreement that governs access to and use of the platform.

Read the terms →

Data Processing

How project and reporting data is processed, stored and retained.

Read the policy →

For security questionnaires, procurement due diligence or contract queries, contact legal@catchment.software.