The short version, in plain terms — for the full legal language see our Terms and Privacy Policy, linked in the site footer.
Data is encrypted with AES-256 at rest and in transit. Personal information such as names and email addresses is stored in encrypted form and only decrypted when needed for display or email delivery.
Every workspace is fully isolated from every other workspace. All queries are scoped to your workspace ID — users in one workspace cannot access data from another.
Role-based access (Manager, Author, Consultant, HR) determines what each person can see and edit. Managers control library scoping per person, and optional multi-factor authentication (TOTP) is available for every account.
Every read, acknowledgement, and administrative action is logged with a timestamp and user identity. Managers can export the full audit trail as PDF or CSV for regulatory inspections at any time.
Our Knowledge Axis supports ISO 27001-aligned documentation management and HIPAA compliance workflows — policy acknowledgement tracking, incident tracking, and audit exports that map to the evidence auditors ask for.
Billing is handled by Stripe. Your card details are never stored on our servers.
Have a specific security question — a vendor questionnaire, a pen-test request, a DPA? We're happy to talk it through.
Contact us