SECURITY & TRUST

Confidential deal work.
Protected by design.

BlueKnight is designed around layered controls for data protection, customer isolation, access management, secure development and operational assurance.

Clear controls. Transparent status. Human accountability.

OUR APPROACH

Security across the
entire data lifecycle.

Protection depends on more than encryption. BlueKnight’s security programme covers how information enters the platform, where it is processed, who can access it, how activity is recorded and how data is retained or deleted.

  1. 01Data entersAuthenticated upload or connected source
  2. 02Secure transmissionTLS in transit across every hop
  3. 03Authorised processingTenant-scoped services only
  4. 04Isolated workspaceLogical separation per customer
  5. 05Controlled accessRole-based access and review
  6. 06Output & exportReviewed and approved by the customer
  7. 07Retention or deletionPer policy and customer request

CONTROL REGISTER

Core security controls.

IDENTITY & ACCESS

The right access.
For the right people.

Access follows least-privilege principles, is reviewed periodically and is removed promptly when no longer required.

01Customer usersWorkspaces, mandates and outputs granted to them by their administrator.
02Customer administratorsManage members, roles and workspace configuration for their organisation.
03BlueKnight supportAuthorised support and engineering personnel may access customer data when required for support, security or legal reasons, under least-privilege controls.
04Technical service identitiesScoped, credential-managed identities used by internal services.
05Third-party servicesOnly approved subprocessors under written data-processing terms.
  • Least privilege
  • Role-based permissions
  • Approval for privileged access
  • Time-limited support access
  • Logging of administrative access
  • Periodic reviews

SECURE DEVELOPMENT

Security throughout
the development lifecycle.

  1. 01DesignThreat considerations captured with the change
  2. 02BuildSeparation of development and production
  3. 03ReviewPeer code review before merge
  4. 04TestStatic analysis, dependency and secrets scanning
  5. 05ReleaseChange approval and protected production branches
  6. 06MonitorRuntime monitoring and vulnerability management
  7. 07ImproveRemediation targets based on severity
  • Peer code review
  • Protected production branches
  • Automated dependency scanning
  • Static application-security testing
  • Secrets scanning
  • Change approval
  • Vulnerability management
  • Patch management

RESILIENCE

Designed to protect
availability and integrity.

BlueKnight maintains operational controls intended to preserve the availability and integrity of the platform, including monitoring, backup and recovery procedures.

Hosting
Established cloud provider with regional isolation
Monitoring
Infrastructure and application monitoring
Backups
Encrypted, tested restoration procedures
Continuity
Documented business-continuity plan
Recovery
Defined disaster-recovery procedures
Capacity
Ongoing capacity and performance monitoring

DATA LIFECYCLE

Know where your data is.
Control how long it remains.

Hosting region, retention and subprocessor arrangements are confirmed with each customer. Approved documentation is available on request.

Hosting region
Confirmed at onboarding
Regional choice
Available on enterprise plans
Active retention
For the duration of the customer contract
Backup retention
Ages out on documented schedule
Account closure
Deletion per the DPA
Early deletion
Available on request
Exports
Downloaded and controlled by the customer

INCIDENT RESPONSE

Prepared to detect,
contain and respond.

BlueKnight maintains an incident-response process covering assessment, containment, recovery, internal escalation and post-incident review. Customer-notification commitments are governed by the Data Processing Agreement.

  1. 01DetectMonitoring and reporting channels
  2. 02AssessSeverity, scope and customer impact
  3. 03ContainIsolate systems and revoke access as needed
  4. 04RecoverRestore service from validated state
  5. 05ReviewPost-incident review and follow-up actions

SUPPLY CHAIN

Security extends to
the services behind ours.

Cloud, model, data, authentication and monitoring providers are reviewed before onboarding and managed under written data-processing terms with minimum contractual safeguards.

  • Security review before onboarding
  • Data-processing agreements
  • Minimum contractual safeguards
  • Ongoing vendor review
  • Access limitation
  • Data-retention restrictions
  • Provider training restrictions
  • Incident-notification obligations

HUMAN IN CHARGE

AI at speed.
Professionals in control.

BlueKnight outputs are designed to be reviewed, challenged and approved by experienced dealmakers. Sources and rationale are visible so users can evaluate the work before it is relied upon. Authorised users remain responsible for their professional judgement and final decisions.

  1. 01 Inspect the source
  2. 02 Review the rationale
  3. 03 Challenge the conclusion
  4. 04 Adjust criteria
  5. 05 Approve or reject the output
  6. 06 Export the completed work

SECURITY REVIEW

Everything your security
team needs to evaluate BlueKnight.

  • Security overviewAvailable on request
  • Data Processing AgreementAvailable on request
  • Subprocessor listAvailable on request
  • Penetration-test executive summaryAvailable under NDA, once issued
  • SOC 2 programme statusAvailable on request
  • Architecture overviewAvailable under NDA
  • Business-continuity overviewAvailable under NDA
  • Security questionnaire responsesAvailable on request
  • Privacy policyPublished
  • Vulnerability-disclosure informationAvailable on request

FREQUENTLY ASKED

Security FAQ.

SECURITY REVIEW

Bring BlueKnight
to your security team.

We can support your review with clear answers on architecture, data handling, model providers, access controls and our assurance programme.