Knowledgeflow Cybersafety Foundation

Trust & Compliance Centre

Welcome to our Trust Centre. As a leader in cybersafety, independent attestation and verifiability matter to us. We manage a robust compliance program designed to set the right example for building trust and demonstrating transparency in our operations.

Got questions about trust and compliance? Trust@Knowledgeflow.org

Safeguards

Data Security

  • Encryption at rest
  • Encryption in transit
  • Data retention controls

Access Control

  • Role-based access
  • Authentification multifactorielle
  • Quarterly access reviews

Infrastructure

  • Cloud environment monitoring
  • Secure configuration standards
  • Business continuity planning

Application Security

  • Secure development lifecycle
  • Vulnerability management
  • Independent security testing

Organizational Security

  • Employee security training
  • Background screening
  • Security policy management

Gestion des risques

  • Incident management
  • Data retention
  • Supply chain security

FAQ

Where is customer data stored?

Customer and operational data is stored only in approved environments and regions selected according to applicable privacy, security, and business requirements.

Do you encrypt customer data?

We use industry-standard encryption for data in transit and at rest wherever the underlying service supports it.

How do you manage security incidents?

We follow a documented process to detect, contain, investigate, remediate, and communicate security incidents.

Do you require multi-factor authentication?

Multi-factor authentication is required for privileged and other sensitive access wherever technically supported.

How often do you perform security testing?

We perform routine vulnerability reviews and risk-based independent security testing on a scheduled basis.

How do you manage employee access?

Access is role-based, approved, reviewed periodically, and removed promptly when it is no longer required.

Do you use third-party service providers?

Third-party providers are assessed before engagement and monitored according to the security and privacy risk of their services.