Trust Center.

KnoxCall takes security seriously. This page is the single canonical source for our security posture, certifications, sub-processors, and incident history.

Audit reports and certificates marked "under NDA" are available to customers and prospects — email [email protected].

Last updated 2026-09-30
  • ISO/IEC 27001:2022 In progress Controls documented; the certification audit is not yet scheduled. Statement of Applicability available under NDA.
  • ISO/IEC 27017:2015 (cloud) In progress Controls implemented. Shared-responsibility matrix available on request.
  • ISO/IEC 27018:2019 (cloud PII) In progress Controls implemented. See the Privacy Policy; self-service DSAR endpoints are built into the product.
  • ISO/IEC 27701:2019 (PIMS) In progress Records of Processing Activities maintained; available under NDA.
  • SOC 2 Type II In progress SOC 2 aligned, Type II in progress.
  • GDPR Compliant Data Processing Addendum
  • NZ Privacy Act 2020 Compliant Privacy Policy
  • HIPAA Optional via BAA Business Associate Agreement available on Pro+ plans.
  • PCI DSS Out of scope Cardholder data is handled by Stripe.

Live security controls.

Nine controls, each stated as it stands today.

  • Encryption at rest AES-256-GCM envelope encryption; per-tenant master keys; BYOK supported.
  • Encryption in transit Dashboard and API served over TLS, 1.3 where the client supports it; HSTS with a two-year max-age, including subdomains; TLS to your upstreams whenever the route's target is https; mTLS between KnoxCall and its static-IP egress servers, and on routes you pin.
  • Authentication OAuth 2.1 + DPoP; passkeys (WebAuthn); SSO (Google, Microsoft, GitHub); workload identity for service accounts.
  • Multi-factor authentication Required for owners and admins on Pro+ plans.
  • Audit logging SHA-256 hash-chained log of account and configuration changes, verified nightly; every proxied call logged with its caller; OTLP export to customer SIEM (Enterprise).
  • Access reviews Quarterly privileged-access reviews; ad-hoc reviews on role changes.
  • Vulnerability management Dependabot, CodeQL, and container scanning on every PR. An independent third-party penetration test is scoped; the tester is not yet engaged. We will publish the assessment summary once the test completes.
  • Backups Our backup policy sets seven-day point-in-time recovery. A yearly full restore drill is due; the first is in November 2026.
  • Incident response Documented runbook; we notify affected customers within 72 hours of becoming aware of a Personal Data Breach affecting their data, as our DPA commits.

The rest of the record.

Suppliers, disclosure, what we share under NDA, and what has happened.

Sub-processors. The canonical list of sub-processors lives at /legal/sub-processors. We notify customers 30 days before adding a sub-processor.

Reporting a vulnerability. Email [email protected]. We acknowledge within 24 hours. Our coordinated disclosure window is 90 days. We do not currently run a paid bug bounty, but we publicly acknowledge contributors.

Documents available under NDA. SOC 2 Type II report (when published), the penetration test summary (once the test completes), our Statement of Applicability, customer-specific architecture diagrams. Email [email protected].

Incident history. When we have a customer-impacting security incident, we publish a postmortem on this page within 5 business days. No customer-impacting security incidents on record.

Elsewhere. Privacy Policy · Data Processing Addendum · Sub-processors · Security Architecture · Status Page · Terms of Service

Store. Proxy. Revoke.

Free for seven days. No card. Your first call in minutes.

All systems operational