KnowledgeCapital

KnowledgeCapital › Docs

Security and data confinement

One database per client, HTTPS, encrypted secrets, per-module rights, two-factor login, audit trail, local AI: where your data sits and who reaches it.

In short. Every client has its own database file: no shared table. Traffic is served over HTTPS, secrets are encrypted at rest, rights are set per module and per action, two-factor authentication is available and every operation is traced. The AI runs on your space's server; the interface loads no third-party script.

The proof of containment: while this block is green, no information from your base can leave your network — and the link lets you check it yourself, attempt by attempt.
The proof of containment: while this block is green, no information from your base can leave your network — and the link lets you check it yourself, attempt by attempt.

Isolation between clients

In the hosted edition, each client has its own database file. Not its own row, not its own column with a tenant identifier — its own file. A query written wrongly cannot return another client's data, because that data is not in the same place.

Where the data sits

The hosted edition runs on a dedicated server at Oracle Cloud Infrastructure. The self-hosted edition runs wherever you put it, including a network with no internet access at all.

In transit and at rest

Access

Personal data

The product handles data about people, and includes the machinery that implies: purpose limitation, retention, planned purge, export and erasure of a person's record, and consent tracking where consent applies.

Bring your security questionsYour CISO wants to see the isolation, the rights, two-factor authentication and the audit trail? Let us show them, or check for yourself in a trial space. Start a free 14-day trial (no card needed) or request a demo.

See also: Verified backups and business continuity · On-premise installation: the sovereign edition · Reversibility: export all your data · Sovereign knowledge management with local AI

Frequently asked questions

Is our data mixed with other clients' data?

No. In the hosted edition, each client has its own database file. A badly written query cannot return another client's data: it is not in the same place.

Does the AI use our data for training?

No. The AI engine runs on the server that hosts your space, on your data and for you. Nothing is sent to an external AI service.

Is two-factor authentication available?

Yes, by time-based code (TOTP) with backup codes, in addition to single sign-on through LDAP, Active Directory or OpenID Connect.

Docs