Security & compliance

Built to pass your security review.

Knodox is designed for teams that audit before they adopt. Every guarantee below is enforced by the platform — not on a roadmap, not a sales promise. This is the full model your IT, security, and compliance teams asked for.

Full audit log Tenant isolation PII masked pre-model Self-host or managed Bring your own AI
How enforcement works

Permissions are enforced at the data layer — not the UI.

Every question runs the same path. Access is decided before a single row is read, and the model only ever sees what the user is allowed to see.

1

Identity resolved from your provider

The user signs in through your existing identity provider. Their groups map to Knodox roles, and their workspace, role, and PII policy are attached to the request — no separate Knodox user directory to keep in sync.

2

Scope compiled before retrieval

Before any data is fetched, the query is compiled with the workspace boundary and row-level rules for that role. Data from other workspaces is not filtered out later — it is never in scope to begin with.

3

Sensitive fields masked before the model

Fields your admins flag as personal or sensitive are masked deterministically before the answer is composed. The AI model never receives the raw value, on every answer.

4

Every figure verified against live data

After the answer is written, each figure is checked back against your data. Anything that can't be traced to a real row is flagged; if the question can't be answered from your data, Knodox says so instead of guessing.

5

Recorded for audit & replay

Identity, the exact scope applied, the sources touched, and the answer all land in an append-only log — with a badge on the answer showing the workspace, role, and PII status that produced it.

The security model

Every control, wired into the platform.

Not on a roadmap, not behind a sales conversation. Read the cards, then take them to your security review.

SOC 2 on our roadmap

Security, availability, and confidentiality controls built to the SOC 2 Type II standard. Formal certification is on our roadmap; we'll walk your team through our controls and architecture under NDA.

Tenant workspace isolation

One isolated workspace per team, business unit, or customer, signed with per-workspace keys and connected to your identity provider. The boundary is enforced by architecture — cross-workspace access is impossible, not merely disallowed.

Read-only by design

Data source connections are rejected at setup time if the credential can write. The read-only guarantee is recorded alongside the connection for your audit log.

Credentials encrypted at rest

Every credential — connection strings, tokens, API keys, identity-provider secrets — is encrypted at rest. The encryption key never leaves the server, and credentials are never written to logs.

Sensitive data masked before the AI sees it

Fields you flag as personal or sensitive are masked before the answer is composed — the AI model never sees the raw value. Your admins choose which fields to protect, self-service, without a Knodox engineer.

Full audit log

Every login, role change, connector creation, query, and AI answer is recorded with timestamp, user, tenant, and scope. Tenant admins can export to CSV for compliance review at any time.

Self-hosted ready

The entire stack deploys with a single command. Bring your own storage, your own file store, and your own AI provider. Nothing leaves your network unless you configure it to.

Bring your own AI provider

Supply your own credentials for Anthropic, OpenAI, Azure OpenAI, or another compatible provider. The AI runs against your account, your billing, your controls — and we never train models on your data.

Clean deletion

Removing a data source deletes both its records and the search index built from them, in the same operation. No orphaned copies linger. Verified and audited.

Security-review FAQ

Answers for your security review.

The questions we get most often from IT, security, and compliance teams. Bring the rest to a call.

Where does our data live? Can we keep it in our own environment?

Yes. The entire stack self-hosts with a single command — bring your own storage, file store, and AI provider, and nothing leaves your network unless you configure it to. Prefer managed? We run it for you. Either way, Knodox reads a read-only copy of your sources; the originals stay where they are.

Do you use our data to train AI models?

No. Knodox does not train models on your data. Retrieval passes only the minimum, permission-scoped, PII-masked context to the model you configure, at query time, to compose a single answer. Because you bring your own AI provider, the model runs under your account and your provider's data-handling terms — not ours.

Which AI model do you use? Can we choose the provider?

You bring your own. Supply credentials for Anthropic, OpenAI, Azure OpenAI, or another compatible provider, and the model runs against your account, your billing, your controls. Swap providers without rewriting anything — the model is a configuration choice, not a lock-in.

How is one customer's data isolated from another's?

Each team, business unit, or customer gets its own isolated workspace, signed with per-workspace keys and connected to your identity provider. The boundary is enforced by architecture, not by application checks — cross-workspace access is impossible, not merely disallowed.

How are permissions and PII enforced — in the UI or the data layer?

At the retrieval layer, not in the UI. Groups from your identity provider map to Knodox roles. Every query is enforced by workspace boundary and PII policy before data is retrieved — sensitive fields are masked before the model reads a single row. Every answer carries a badge showing the workspace, role, and PII status that produced it, and lands in the audit log.

How do you stop the AI from making up numbers?

Answers are grounded in real data pulled from your systems, and every figure is checked back against your live data after the answer is written. Anything that can't be traced to a real row is flagged, and if a question can't be answered from your data, Knodox says so instead of guessing. Sources are cited inline on every answer.

What happens to our data if we remove a source or leave?

Removing a data source deletes both its records and the search index built from them in the same operation — no orphaned copies linger. The deletion is verified and recorded in the audit log.

Are you SOC 2 compliant?

Not yet certified — and we won't claim otherwise. Our security, availability, and confidentiality controls are built to the SOC 2 Type II standard, and formal certification is on our roadmap. In the meantime we're happy to walk your team through our controls and architecture under NDA.

Take it to your security review.

Thirty minutes with our team, or the SOC 2 report under NDA. We come prepared to answer your IT, security, and compliance questions — no demo data, no slideware.