KnoxCall takes security seriously. This page is the single canonical source for our security posture, certifications, sub-processors, and incident history.
Audit reports and certificates marked "under NDA" are available to customers and prospects — email [email protected].
Last updated 2026-09-30Nine controls, each stated as it stands today.
Suppliers, disclosure, what we share under NDA, and what has happened.
Sub-processors. The canonical list of sub-processors lives at /legal/sub-processors. We notify customers 30 days before adding a sub-processor.
Reporting a vulnerability. Email [email protected]. We acknowledge within 24 hours. Our coordinated disclosure window is 90 days. We do not currently run a paid bug bounty, but we publicly acknowledge contributors.
Documents available under NDA. SOC 2 Type II report (when published), the penetration test summary (once the test completes), our Statement of Applicability, customer-specific architecture diagrams. Email [email protected].
Incident history. When we have a customer-impacting security incident, we publish a postmortem on this page within 5 business days. No customer-impacting security incidents on record.
Elsewhere. Privacy Policy · Data Processing Addendum · Sub-processors · Security Architecture · Status Page · Terms of Service
Free for seven days. No card. Your first call in minutes.