Trust center

Everything your security team needs to say yes.

Knovara runs as one isolated deployment in your own cloud, so most of what a review asks about is decided by your account and controls. The documents below explain exactly how — the architecture, the permissions, and where every kind of data goes. Contract artifacts are available on request.

On request

Available under NDA

Contract and assurance artifacts. Tell us who you are and what you need; we send them to your team, usually within two business days.

Data Processing Agreement (DPA)

Our standard data-processing terms, including subprocessor terms and international-transfer provisions, for your legal team to review and sign.

Request →

Security questionnaire response

Our written answers to a standard security questionnaire (e.g. CAIQ / SIG-lite), or to yours.

Request →

Deletion-record and offboarding-checklist sample

An example of the deletion record and admin verification checklist produced at offboarding (FR17).

Request →

Full permission matrix and consent text

The endpoint-by-endpoint permission matrix and the exact admin-consent text shown in Entra.

Request →

Architecture deep-dive / review call

A working session with our engineering team to walk your architects through the deployment, threat model and controls.

Request →
The short version

Why the review is shorter than usual.

  • It runs in your cloud. The deployment, the database and the AI model service are all in your own AWS or Azure account — not a shared multi-tenant service we operate.
  • No standing access to your documents. Knovara reads SharePoint only as the signed-in person, only at the moment of the request.
  • No document text is stored. Not in the database, logs, analytics or error messages.
  • We are honest about assurance. No SOC 2 or ISO certification yet, and we will not imply otherwise.