Enterprise controls, on by default
Encryption
Data is encrypted in transit and at rest across the platform.
Data Isolation
Strict multi-tenant isolation; every tenant's data is logically separated.
Role-Based Access
Granular Owner, Admin and Member roles with least-privilege defaults.
Audit Logs
Every knowledge action and administrative change is logged for review.
Explainability
Health, Risk and Readiness scores trace back to the signals that produced them.
Grounded Retrieval
Coach answers are generated from validated, in-scope knowledge with citations.
Secure Hosting
Deployed on hardened, monitored cloud infrastructure.
GDPR Ready
Data protection by design and by default across the product.
AI, knowledge and responsible use
AI Governance
Policy controls over what content is used for AI retrieval, how, and by whom.
Knowledge Governance
Owner → Admin → Approver validation ladder for every knowledge asset.
Responsible AI
Grounded, cited answers; unvalidated, archived or soft-deleted assets never reach Coach.
Bias & Safety
Guardrails around unsafe or out-of-scope outputs, reviewable by administrators.
Data protection by design
Knowva is built around GDPR principles of data minimisation, purpose limitation and accountability. Customers control what knowledge is ingested and who can see it. Personal data is processed only as required to deliver the service.
Employees participate in knowledge capture on a consent basis. Owners can archive or soft-delete content, and archived or soft-deleted assets are excluded from AI retrieval.
Where we are, and where we're going
GDPR
Data protection by design and by default across the platform.
SOC 2 Type II
Controls designed against SOC 2 Type II criteria. Formal certification is on our roadmap.
Additional frameworks
Additional certifications are being evaluated based on customer needs.
This page describes current posture and roadmap intent. It is not, on its own, an independent certification.
Layered, multi-tenant, governed
A conceptual view — see How It Works for the full pipeline.
Trust roadmap
- SOC 2 Type II certification — in progress
- Additional regional hosting options — planned
- Expanded customer-facing audit reporting — planned
- Additional identity provider integrations — planned
Live status page
A public status page is planned. In the interim, enterprise customers can request status information through their account contact.