SECURITY & TRUST

Your Data Stays Yours

Security isn't a feature at Knowi, it's the foundation. From architecture to AI, every layer is built to keep data in your environment, under your control.

SOC 2 Type II Certified
AES-256 Encryption
Private AI / No External LLMs
On-Premises Available
01 / ARCHITECTURE

Data Stays in Your Environment

Knowi queries your databases directly using native protocols. No data is copied into proprietary storage. Results are held in a configurable, temporary cache, then discarded.

02 / ENCRYPTION

Encrypted at Every Layer

AES-256 encryption for credentials and cached results at rest. TLS 1.2+ for all traffic in transit. Optional IP whitelisting, SSL/SSH tunneling, and private deployments.

03 / GOVERNANCE

Enterprise Governance

SSO via SAML & OpenID Connect, 2FA, LDAP, role-based access control, row-level security, multi-tenancy isolation, and full audit trails.

DATA FLOW

How Knowi Handles Your Data

Knowi generates a secure query, retrieves only the result, and stores it in a temporary cache. Your source data never moves.

Minimal Data MovementOnly query results leave the source, never raw tables or exports
Your Security ModelKnowi respects your database's existing auth, firewall, and encryption policies
No Long-Term StorageCached results auto-expire. No sensitive data persisted beyond your configured window
Query Path
01Your DatabasesMongoDB, ES, SQL, APIs
02Knowi Query EngineNative protocol, read-only
03Temp CacheConfigurable, auto-expires
04Dashboard / EmbedBrowser or embedded app
CONTROLS

Security Controls in Detail

Encryption & Connections

AES-256 encryption for credentials and cached results at rest
TLS 1.2+ for all traffic between browser and Knowi Cloud
IP whitelisting to restrict access by network
SSL/SSH tunneling for database connections behind firewalls
Private deployments, cloud VPC or fully on-premises

Authentication

Two-factor authentication (2FA)
LDAP integration for directory-based auth
SSO via SAML and OpenID Connect
Session management and automatic timeout policies

Access Controls

Role-based access control (RBAC)
Row-level security, users see only their authorized data
Multi-tenancy isolation, per-tenant data boundaries
User activity auditing and login tracking
Query history with rollback capabilities

Compliance & Governance

GDPR, data minimization, right to erasure support
HIPAA, BAA available, PHI never stored long-term
Suitable for finance, government, healthcare environments
Full audit trail of data access, queries, and user actions
PRIVATE AI

Own AI. No Third-Party Data Leakage.

Knowi AI is the default. Models, inference, and vector search all stay inside the Knowi boundary, so no third-party LLM sees your queries or your results. Third-party models are an option, not a dependency: you can enable OpenAI or Claude per feature if you want them, and switch anytime.

Knowi AI by defaultModels, inference, and vector search on Knowi infrastructure, not a wrapper around someone else's LLM
Third-party models optionalChoose OpenAI or Claude per feature, or keep everything on Knowi AI. No vendor lock-in
Your choice of deploymentManaged cloud, on-premises, hybrid, or air-gapped
Run it fully localOn-premises customers run the full platform, all agents, and their own LLM via Docker or Kubernetes
Document AIQuery PDFs, Word files, and unstructured docs privately
HIPAA & GDPR compatibleMeets strictest data residency requirements
Where Inference Runs
Default: Knowi AI
Knowi Private LLM
Vector Search
Document AI Engine
Optional, opt-in
OpenAI
Claude
Any model you enable
Deploy on Knowi cloud, on-premises, hybrid, or air-gapped
SOC 2
Type II Report
Available upon request. Contact support@knowi.com

Platform Compliance

Knowi maintains comprehensive IT controls regularly audited by independent firms. Our control procedures have been verified in a SOC 2 Type II report prepared in accordance with AICPA attestation standards and ISAE international standards.

RESPONSIBLE DISCLOSURE

Vulnerability Reporting

01

Report

Email support@knowi.com with product info, vulnerability type, reproduction steps, and screenshots.

02

Evaluate

You'll receive a response within one business day. All reports remain confidential and are shared only with the team needed to fix the issue.

03

Resolve

After evaluation, a fix is developed and deployed. Security notifications are sent to customers via product update emails.

Testing Guidelines

Vulnerability scans and bug hunting should be performed on the staging environment: staging.knowi.com. For questions about this policy, contact support@knowi.com. Knowi reserves the right to update this policy at any time.

Unify. Analyze. Act.

AI-powered analytics across every data source. No warehouse required.

SECURITY & TRUST

Your Data Stays Yours

Security isn't a feature at Knowi - it's the foundation. From architecture to AI, every layer is built to keep data in your environment, under your control.

SOC 2 Type II Certified AES-256 Encryption Private AI / No External LLMs On-Premises Available

Data Stays in Your Environment

Knowi queries your databases directly using native protocols. No data is copied into proprietary storage. Results are held in a configurable, temporary cache - then discarded.

Encrypted at Every Layer

AES-256 encryption for credentials and cached results at rest. TLS 1.2+ for all traffic in transit. Optional IP whitelisting, SSL/SSH tunneling, and private deployments.

Enterprise Governance

SSO via SAML & OpenID Connect, 2FA, LDAP, role-based access control, row-level security, multi-tenancy isolation, and full audit trails.

How Knowi Handles Your Data

Knowi generates a secure query, retrieves only the result, and stores it in a temporary cache. Your source data never moves.

Your Databases
MongoDB, ES, SQL, APIs
Knowi Query Engine
Native protocol, read-only
Temp Cache
Configurable, auto-expires
Dashboard / Embed
Browser or embedded app
Minimal Data Movement Only query results leave the source, never raw tables or exports
Your Security Model Knowi respects your database's existing auth, firewall, and encryption policies
No Long-Term Storage Cached results auto-expire. No sensitive data persisted beyond your configured window

Security Controls in Detail

Encryption & Connections

  • AES-256 encryption for credentials and cached results at rest
  • TLS 1.2+ for all traffic between browser and Knowi Cloud
  • IP whitelisting to restrict access by network
  • SSL/SSH tunneling for database connections behind firewalls
  • Private deployments - cloud VPC or fully on-premises

Authentication

  • Two-factor authentication (2FA)
  • LDAP integration for directory-based auth
  • SSO via SAML and OpenID Connect
  • Session management and automatic timeout policies

Access Controls

  • Role-based access control (RBAC)
  • Row-level security - users see only their authorized data
  • Multi-tenancy isolation - per-tenant data boundaries
  • User activity auditing and login tracking
  • Query history with rollback capabilities

Compliance & Governance

  • GDPR - data minimization, right to erasure support
  • HIPAA - BAA available, PHI never stored long-term
  • Suitable for finance, government, healthcare environments
  • Full audit trail of data access, queries, and user actions
Private AI

AI That Never Leaves Your Infrastructure

Knowi's Private AI runs on small language model, inside your environment. Natural language queries, Document AI, and AI-powered insights - all processed on-premises or in private cloud. No data is ever sent to OpenAI, Google, or any external AI service.

On-premises LLM - runs inside your firewall on your hardware
Natural language queries on unmodeled NoSQL, SQL, and API data
Document AI - query PDFs, Word files, and unstructured docs privately
Zero external API calls - no data sent to third-party LLM providers
HIPAA & GDPR compatible - meets strictest data residency requirements
Your Infrastructure
Knowi Private LLM
Your Databases
Document AI Engine
External Services
OpenAI / ChatGPT
Google Gemini
Any External LLM

Platform Compliance

Knowi maintains comprehensive IT controls regularly audited by independent firms. Our control procedures have been verified in a SOC 2 Type II report prepared in accordance with AICPA attestation standards and ISAE international standards.

Knowi's SOC 2 report is available upon request. Contact support@knowi.com

Vulnerability Reporting

Report

Email support@knowi.com with product info, vulnerability type, reproduction steps, and screenshots.

Evaluate

You'll receive a response within one business day. All reports remain confidential and are shared only with the team needed to fix the issue.

Resolve

After evaluation, a fix is developed and deployed. Security notifications are sent to customers via product update emails.

Testing Guidelines

Vulnerability scans and bug hunting should be performed on the staging environment: staging.knowi.com

For questions about this policy, contact support@knowi.com. Knowi reserves the right to update this policy at any time.

Unify. Analyze. Act.

AI-powered analytics across every data source. No warehouse required.