Trust Center

The controls behind a system regulated buyers can adopt.

Knowledge Foundry is built for organizations that must defend how their knowledge is produced, stored, and delivered. This page summarizes the security posture, the compliance posture, and the data handling that make the platform adoptable inside a regulated environment. Sub pages provide the detail.

Posture at a glance

What we are, what we are working toward, and how we say it honestly.

Certifications are named as certified, in progress, or aligned. In progress means the control set is implemented and audited against. The certificate itself is not yet issued.

ISO 27001, aligned

Information security controls are designed against ISO/IEC 27001. Formal certification is in progress. Documentation and audit trail are available to enterprise buyers under NDA.

SOC 2 Type II, in progress

Operating in the observation window against the Trust Services Criteria for Security, Availability, and Confidentiality. Report available to prospective customers upon completion.

APRA CPS 234, aware

For regulated Australian financial services customers, controls, evidence artifacts, and reporting are designed to support obligations under CPS 234 and to fit inside an environment regulated by APRA.

GDPR, ready by design

Data processing terms, subprocessor register, deletion workflows, and export mechanisms are structured for processing eligible under GDPR where a customer requires them.

WCAG 2.1 AA

The customer surface (Studio, Console, and delivered programs) is engineered against WCAG 2.1 AA. See our accessibility statement for testing methodology and known limitations.

Data residency in Australia

Production data for Australian customers resides in AWS ap-southeast-2 (Sydney). No routine offshore replication. Residency in other regions is available on request for regulated deployments.

Controls

How the platform is defended.

Encryption in transit and at rest

TLS 1.3 across all customer facing endpoints. AES-256 encryption at rest for databases and object storage. Keys managed in AWS KMS with separation per tenant.

Access model

SSO/SAML for customer sign in, MFA required for staff access, principle of least privilege on internal systems, and isolation per tenant on production data.

Infrastructure

Hosted on AWS, ap-southeast-2 by default. Segmented VPCs. Immutable infrastructure via versioned deployment pipelines. No shared build hosts.

Personnel

Staff access is scoped, logged, and reviewed. Background checks on engineering and support roles that touch customer environments. Security training on hire and annually.

Incident response

Documented response playbook with named on call rotation. Customer notification for material incidents is committed to within contractually defined windows.

Backups and recovery

Automated daily backups with point in time recovery, tested restore drills, and documented recovery time and recovery point objectives available under NDA.

Data handling

Where your data lives, and who touches it.

Customer data for Australian tenants is processed and stored in AWS ap-southeast-2 (Sydney) by default. There is no routine replication to overseas regions. Backups are encrypted, held in the same region, and retained on a defined schedule.

Access to production is limited to a named group of engineers, scoped to specific tasks, logged, and reviewed. Support staff do not have standing read access to customer content. Access is granted for a specific ticket and revoked automatically.

Ownership. Your source material, frameworks, generated content, review history, and evidence artifacts are yours. On exit, the full corpus is exportable in structured form. We do not train third party models on customer content.

Subprocessors

Who processes data on our behalf.

The current subprocessor register is maintained on the compliance posture page and provided in full to prospective customers. Categories at a high level are listed below.

Cloud infrastructure

Amazon Web Services (ap-southeast-2, Sydney). Hosting, compute, storage, key management. No offshore replication for tenants hosted in Australia.

Observability

Application performance monitoring and error tracking. Non customer content only. PII scrubbed at source.

Email delivery

Transactional email for account and workflow notifications only. Not used for marketing to end users.

Incident response

What happens when something goes wrong.

Each security event is triaged against a documented playbook. Material incidents that affect customer data trigger a named on call rotation, a designated incident commander, and a written post incident review. Customer notification for material incidents is committed to within contractually defined windows in the master services agreement.

For information on our responsible disclosure program, or to report a suspected vulnerability, see the security page. The security contact is security@knowledge-foundry.com.

For enterprise procurement

Request the full security pack.

A 45 minute working session with our team, plus the security pack, DPA, and subprocessor register under NDA. We reply within one business day.

We reply within one business day.