Knowledge Catalyst
    Trust Center

    Security, privacy, and compliance

    Knowledge Catalyst builds digital trust infrastructure — transparent, traceable, and tamper-evident. This page summarises the international standards our security and privacy programme is built around, and how we handle your data.

    Standards

    The standards we build around

    Each standard below shows its current status. Certificate numbers and copies are available on request under NDA.

    ISO/IEC 27001:2022

    Information Security Management

    Certified

    The international standard for an Information Security Management System (ISMS): a risk-based framework for protecting the confidentiality, integrity, and availability of information, independently audited and continually improved.

    Certificate no.
    SCS 102876DIS
    Issued by
    SOCOTEC
    ISO/IEC 27701:2019

    Privacy Information Management

    Certified

    A privacy extension to ISO/IEC 27001 specifying a Privacy Information Management System (PIMS) for handling personally identifiable information as a controller and/or processor, mapped closely to regimes like the GDPR.

    Certificate no.
    SCS 102876 PII
    Issued by
    SOCOTEC
    ISO/IEC 27017:2015

    Cloud Security Controls

    Certified

    A code of practice for information security controls for cloud services, adding cloud-specific guidance and clarifying the shared-responsibility split between cloud provider and customer.

    Certificate no.
    SCS 700081
    Issued by
    SOCOTEC
    ISO/IEC 27018:2025

    PII Protection in Public Clouds

    Certified

    A code of practice for protecting personally identifiable information (PII) in public clouds where the provider acts as a processor — processing PII only on documented instructions, with transparency on sub-processors and data locations.

    Certificate no.
    SCS 700081
    Issued by
    SOCOTEC
    Data

    Data residency & transfers

    Knowledge Catalyst collects information globally and primarily stores it in Singapore. For international transfers we implement Standard Contractual Clauses (SCCs) or rely on Binding Corporate Rules (BCRs) to ensure lawful transfer under the GDPR and PDPA.

    For a full list of sub-processors, our latest audit evidence, or a copy of a specific certificate, contact our security team — we share documentation with prospective and existing customers under NDA where appropriate.