Features
Catégo covers your entire information security and privacy compliance journey — from asset inventory all the way to presentation-ready exports.
Pillar 1
Assess each asset across the four dimensions of the DICT model — Availability, Integrity, Confidentiality, and Traceability — to set a sensitivity level and prioritize the appropriate protection measures.
Foundation
Categorization and the register both build on a structured inventory. Record and connect everything that matters to your compliance.
Pillar 2
Document each personal information processing activity and keep your register up to date, ready to present to the Commission d'accès à l'information or another authority.
Pillar 3
Produce your privacy impact assessments faster, with a structured draft generated by the AI and validated by an authorized person.
Add-on module
For clients who also use Moelleux — Horizon-Cumulus's consent management platform — drive your cookie banners and policies directly from Catégo, without leaving your compliance workspace.
Only need a cookie manager? Moelleux can also be used on its own.
Catégo for compliance, Moelleux for visitor consent. Together, a complete record — from your information inventory to your website's cookie banner.
AI assistant
The assistant speeds up every step without ever deciding for you.
Describe an activity or asset in plain language; the AI extracts a structured record that you complete.
The AI proposes a level for each DICT dimension and drafts the justification, which you adjust as needed.
Data likely to be personal information is flagged so nothing is missed in the register.
A draft impact assessment is produced from your existing data, clearly labelled "AI-generated".
You keep control and traceability: every AI-generated item is reviewed and approved by an authorized person before it is kept.
Demo
Watch how to document your privacy compliance — AI-assisted.
Generate your records of processing and your impact assessments as PDFs, formatted to hand to management, a client, or a supervisory authority.
Law 25, GDPR and PIPEDA are fully supported. The data model is multi-regime from day one: each framework's specifics are added as extensions, no rebuild. Every regime brings its own obligations catalogue, legal bases and assessment instrument.
Operational compliance
Track your obligations, draft your documents and answer requests — all in one place.
A catalogue of each regime's obligations (Law 25, GDPR, PIPEDA), with status, owner and evidence — feeding your compliance index.
Privacy and governance policies, collection notices, procedures, processor agreements (DPA): a draft written from your context, which you validate.
A register of access, rectification, erasure and portability requests, with automatic statutory deadline computation (30 days / 1 month) and overdue tracking.
Unique to Catégo
Your vendors and business customers are often on Catégo too. Link who hosts what — without ever exchanging personal information — and turn the controller ↔ processor relationship into a living link.
A B2B governance registry: Catégo links organisations, never your end customers.
Any organisation can be a consumer of a service; as soon as it hosts one for others, it also becomes the provider. Each link documents its part and notifies the relevant link on an incident.