Everything your security team needs to say yes.
Knovara runs as one isolated deployment in your own cloud, so most of what a review asks about is decided by your account and controls. The documents below explain exactly how — the architecture, the permissions, and where every kind of data goes. Contract artifacts are available on request.
Public documents
Open, versioned, and the same for everyone. No form, no wait.
Architecture and isolation
How a Knovara deployment is built: one isolated stack per customer in your own cloud, an in-stack control plane, and no vendor standing access.
Read →Microsoft 365 permissions
The exact delegated Graph scopes Knovara requests, what each is used for, and the scopes it explicitly never requests.
Read →Data handling and retention
What Knovara keeps and never keeps, where it lives, and the retention and deletion schedule for each data class.
Read →Subprocessors
Who processes what. Most processing happens inside your own cloud account under your own agreements; our own subprocessors are few and named.
Read →Disconnect and offboarding
What happens when you pause or disconnect: work stops immediately, data is purged on the retention schedule, and offboarding produces a deletion record.
Read →Available under NDA
Contract and assurance artifacts. Tell us who you are and what you need; we send them to your team, usually within two business days.
Data Processing Agreement (DPA)
Our standard data-processing terms, including subprocessor terms and international-transfer provisions, for your legal team to review and sign.
Request →Security questionnaire response
Our written answers to a standard security questionnaire (e.g. CAIQ / SIG-lite), or to yours.
Request →Deletion-record and offboarding-checklist sample
An example of the deletion record and admin verification checklist produced at offboarding (FR17).
Request →Full permission matrix and consent text
The endpoint-by-endpoint permission matrix and the exact admin-consent text shown in Entra.
Request →Architecture deep-dive / review call
A working session with our engineering team to walk your architects through the deployment, threat model and controls.
Request →Why the review is shorter than usual.
- It runs in your cloud. The deployment, the database and the AI model service are all in your own AWS or Azure account — not a shared multi-tenant service we operate.
- No standing access to your documents. Knovara reads SharePoint only as the signed-in person, only at the moment of the request.
- No document text is stored. Not in the database, logs, analytics or error messages.
- We are honest about assurance. No SOC 2 or ISO certification yet, and we will not imply otherwise.