Knowledgeflow Cybersafety Foundation
Trust & Compliance Centre
Welcome to our Trust Centre. As a leader in cybersafety, independent attestation and verifiability matter to us. We manage a robust compliance program designed to set the right example for building trust and demonstrating transparency in our operations.
Got questions about trust and compliance? Trust@Knowledgeflow.org
Safeguards
Data Security
- Encryption at rest
- Encryption in transit
- Data retention controls
Access Control
- Role-based access
- Autenticación multifactor
- Quarterly access reviews
Infrastructure
- Cloud environment monitoring
- Secure configuration standards
- Business continuity planning
Application Security
- Secure development lifecycle
- Vulnerability management
- Independent security testing
Organizational Security
- Employee security training
- Background screening
- Security policy management
Gestión de riesgos
- Incident management
- Data retention
- Supply chain security
FAQ
Where is customer data stored?
Customer and operational data is stored only in approved environments and regions selected according to applicable privacy, security, and business requirements.
Do you encrypt customer data?
We use industry-standard encryption for data in transit and at rest wherever the underlying service supports it.
How do you manage security incidents?
We follow a documented process to detect, contain, investigate, remediate, and communicate security incidents.
Do you require multi-factor authentication?
Multi-factor authentication is required for privileged and other sensitive access wherever technically supported.
How often do you perform security testing?
We perform routine vulnerability reviews and risk-based independent security testing on a scheduled basis.
How do you manage employee access?
Access is role-based, approved, reviewed periodically, and removed promptly when it is no longer required.
Do you use third-party service providers?
Third-party providers are assessed before engagement and monitored according to the security and privacy risk of their services.
