The controls behind a system regulated buyers can adopt.
Knowledge Foundry is built for organizations that must defend how their knowledge is produced, stored, and delivered. This page summarizes the security posture, the compliance posture, and the data handling that make the platform adoptable inside a regulated environment. Sub pages provide the detail.
What we are, what we are working toward, and how we say it honestly.
Certifications are named as certified, in progress, or aligned. In progress means the control set is implemented and audited against. The certificate itself is not yet issued.
ISO 27001, aligned
Information security controls are designed against ISO/IEC 27001. Formal certification is in progress. Documentation and audit trail are available to enterprise buyers under NDA.
SOC 2 Type II, in progress
Operating in the observation window against the Trust Services Criteria for Security, Availability, and Confidentiality. Report available to prospective customers upon completion.
APRA CPS 234, aware
For regulated Australian financial services customers, controls, evidence artifacts, and reporting are designed to support obligations under CPS 234 and to fit inside an environment regulated by APRA.
GDPR, ready by design
Data processing terms, subprocessor register, deletion workflows, and export mechanisms are structured for processing eligible under GDPR where a customer requires them.
WCAG 2.1 AA
The customer surface (Studio, Console, and delivered programs) is engineered against WCAG 2.1 AA. See our accessibility statement for testing methodology and known limitations.
Data residency in Australia
Production data for Australian customers resides in AWS ap-southeast-2 (Sydney). No routine offshore replication. Residency in other regions is available on request for regulated deployments.
How the platform is defended.
Encryption in transit and at rest
TLS 1.3 across all customer facing endpoints. AES-256 encryption at rest for databases and object storage. Keys managed in AWS KMS with separation per tenant.
Access model
SSO/SAML for customer sign in, MFA required for staff access, principle of least privilege on internal systems, and isolation per tenant on production data.
Infrastructure
Hosted on AWS, ap-southeast-2 by default. Segmented VPCs. Immutable infrastructure via versioned deployment pipelines. No shared build hosts.
Personnel
Staff access is scoped, logged, and reviewed. Background checks on engineering and support roles that touch customer environments. Security training on hire and annually.
Incident response
Documented response playbook with named on call rotation. Customer notification for material incidents is committed to within contractually defined windows.
Backups and recovery
Automated daily backups with point in time recovery, tested restore drills, and documented recovery time and recovery point objectives available under NDA.
Where your data lives, and who touches it.
Customer data for Australian tenants is processed and stored in AWS ap-southeast-2 (Sydney) by default. There is no routine replication to overseas regions. Backups are encrypted, held in the same region, and retained on a defined schedule.
Access to production is limited to a named group of engineers, scoped to specific tasks, logged, and reviewed. Support staff do not have standing read access to customer content. Access is granted for a specific ticket and revoked automatically.
Ownership. Your source material, frameworks, generated content, review history, and evidence artifacts are yours. On exit, the full corpus is exportable in structured form. We do not train third party models on customer content.
Who processes data on our behalf.
The current subprocessor register is maintained on the compliance posture page and provided in full to prospective customers. Categories at a high level are listed below.
Cloud infrastructure
Amazon Web Services (ap-southeast-2, Sydney). Hosting, compute, storage, key management. No offshore replication for tenants hosted in Australia.
Observability
Application performance monitoring and error tracking. Non customer content only. PII scrubbed at source.
Email delivery
Transactional email for account and workflow notifications only. Not used for marketing to end users.
What happens when something goes wrong.
Each security event is triaged against a documented playbook. Material incidents that affect customer data trigger a named on call rotation, a designated incident commander, and a written post incident review. Customer notification for material incidents is committed to within contractually defined windows in the master services agreement.
For information on our responsible disclosure program, or to report a suspected vulnerability, see the security page. The security contact is security@knowledge-foundry.com.
Where this fits in the system.
Request the full security pack.
A 45 minute working session with our team, plus the security pack, DPA, and subprocessor register under NDA. We reply within one business day.
We reply within one business day.