Knight Trust Center
Transparency is the foundation of trust. Here's everything you need to know about how Knight operates, protects your data, and keeps its systems reliable.
All Systems Operational
Real-time status monitoring coming soon.
Service Reliability
99.9%
Target uptime SLA
30d
Rolling uptime windowLive data available soon
48h
Advance notice for maintenance windows
Infrastructure
Built on enterprise-grade, globally distributed infrastructure with no single points of failure.
Edge Network
Vercel Edge Network
Globally distributed CDN with automatic routing to the nearest region.
Database
Supabase PostgreSQL
Managed Postgres with built-in replication, backups, and row-level security.
Distribution
Globally Distributed
Infrastructure spans multiple regions to minimize latency for all users.
Resilience
Automated Failover
Traffic is automatically rerouted within seconds of any regional degradation.
Security Practices
Security is engineered in, not bolted on.
- SOC 2 Type II audit in progress
- End-to-end TLS 1.3 encryption for all data in transit
- AES-256 encryption for all data at rest
- Role-based access control across all internal systems
- Multi-factor authentication enforced for all staff accounts
- Automated dependency vulnerability scanning on every deploy
- Secrets management via environment-isolated vaults
- Regular third-party penetration testing
Privacy Commitments
Your data belongs to you. We are stewards, not owners.
GDPR-Conscious Design
Knight is designed with GDPR principles as a baseline, not an afterthought. Data subject rights are built into the product, not handled manually.
No Data Selling
We do not sell, license, or trade your data with any third party for any purpose, ever. Our business model is subscriptions, not your information.
User-Controlled Data
Export your data, update it, or request deletion at any time. You have full control over what Knight stores about you and your organization.
Data Handling Principles
Six principles that govern every decision we make about your data.
Data Minimization
We collect only what is strictly necessary to deliver Knight's functionality. No excess data is ingested, stored, or processed.
Purpose Limitation
Data collected for one purpose is never repurposed without explicit consent. Every data flow has a documented, bounded reason.
Storage Security
All data is encrypted at rest using AES-256 and in transit via TLS 1.3. Database access is scoped, audited, and rotated regularly.
Transparent Processing
We document what we process, why we process it, and how long we retain it. No hidden pipelines. No silent enrichment.
User Control
You can export, correct, or delete your data at any time from your account settings. Requests are fulfilled within 72 hours.
No Third-Party Sale
Your data is never sold, rented, or traded to third parties. Period. We are not in the business of monetizing your information.
Maintenance Policy
We take maintenance seriously so you don't have to think about it.
Scheduled Windows
All planned maintenance is scheduled during the lowest-traffic windows — typically between 02:00–05:00 UTC on weekdays.
48-Hour Advance Notice
Non-emergency maintenance is communicated at least 48 hours in advance via in-app banner and email notification.
Zero-Downtime Deploys
Application deployments use blue-green and rolling strategies. Most updates reach production with no user-visible interruption.
Responsible Disclosure
Found a vulnerability? We take security reports seriously and respond within 24 hours. Please disclose responsibly — do not publish or exploit findings before we've had a chance to address them.
Report a Vulnerabilitysecurity@knightagency.tech · PGP key available on request