SECURITY & TRUST
Confidential deal work.
Protected by design.
BlueKnight is designed around layered controls for data protection, customer isolation, access management, secure development and operational assurance.
Clear controls. Transparent status. Human accountability.
OUR APPROACH
Security across the
entire data lifecycle.
Protection depends on more than encryption. BlueKnight’s security programme covers how information enters the platform, where it is processed, who can access it, how activity is recorded and how data is retained or deleted.
- 01Data entersAuthenticated upload or connected source
- 02Secure transmissionTLS in transit across every hop
- 03Authorised processingTenant-scoped services only
- 04Isolated workspaceLogical separation per customer
- 05Controlled accessRole-based access and review
- 06Output & exportReviewed and approved by the customer
- 07Retention or deletionPer policy and customer request
CONTROL REGISTER
Core security controls.
IDENTITY & ACCESS
The right access.
For the right people.
Access follows least-privilege principles, is reviewed periodically and is removed promptly when no longer required.
- Least privilege
- Role-based permissions
- Approval for privileged access
- Time-limited support access
- Logging of administrative access
- Periodic reviews
SECURE DEVELOPMENT
Security throughout
the development lifecycle.
- 01DesignThreat considerations captured with the change
- 02BuildSeparation of development and production
- 03ReviewPeer code review before merge
- 04TestStatic analysis, dependency and secrets scanning
- 05ReleaseChange approval and protected production branches
- 06MonitorRuntime monitoring and vulnerability management
- 07ImproveRemediation targets based on severity
- Peer code review
- Protected production branches
- Automated dependency scanning
- Static application-security testing
- Secrets scanning
- Change approval
- Vulnerability management
- Patch management
RESILIENCE
Designed to protect
availability and integrity.
BlueKnight maintains operational controls intended to preserve the availability and integrity of the platform, including monitoring, backup and recovery procedures.
- Hosting
- Established cloud provider with regional isolation
- Monitoring
- Infrastructure and application monitoring
- Backups
- Encrypted, tested restoration procedures
- Continuity
- Documented business-continuity plan
- Recovery
- Defined disaster-recovery procedures
- Capacity
- Ongoing capacity and performance monitoring
DATA LIFECYCLE
Know where your data is.
Control how long it remains.
Hosting region, retention and subprocessor arrangements are confirmed with each customer. Approved documentation is available on request.
Privacy Policy →Data Processing Agreement →Subprocessor list →
- Hosting region
- Confirmed at onboarding
- Regional choice
- Available on enterprise plans
- Active retention
- For the duration of the customer contract
- Backup retention
- Ages out on documented schedule
- Account closure
- Deletion per the DPA
- Early deletion
- Available on request
- Exports
- Downloaded and controlled by the customer
INCIDENT RESPONSE
Prepared to detect,
contain and respond.
BlueKnight maintains an incident-response process covering assessment, containment, recovery, internal escalation and post-incident review. Customer-notification commitments are governed by the Data Processing Agreement.
- 01DetectMonitoring and reporting channels
- 02AssessSeverity, scope and customer impact
- 03ContainIsolate systems and revoke access as needed
- 04RecoverRestore service from validated state
- 05ReviewPost-incident review and follow-up actions
SUPPLY CHAIN
Security extends to
the services behind ours.
Cloud, model, data, authentication and monitoring providers are reviewed before onboarding and managed under written data-processing terms with minimum contractual safeguards.
- Security review before onboarding
- Data-processing agreements
- Minimum contractual safeguards
- Ongoing vendor review
- Access limitation
- Data-retention restrictions
- Provider training restrictions
- Incident-notification obligations
HUMAN IN CHARGE
AI at speed.
Professionals in control.
BlueKnight outputs are designed to be reviewed, challenged and approved by experienced dealmakers. Sources and rationale are visible so users can evaluate the work before it is relied upon. Authorised users remain responsible for their professional judgement and final decisions.
- 01 Inspect the source
- 02 Review the rationale
- 03 Challenge the conclusion
- 04 Adjust criteria
- 05 Approve or reject the output
- 06 Export the completed work
SECURITY REVIEW
Everything your security
team needs to evaluate BlueKnight.
- Security overviewAvailable on request
- Data Processing AgreementAvailable on request
- Subprocessor listAvailable on request
- Penetration-test executive summaryAvailable under NDA, once issued
- SOC 2 programme statusAvailable on request
- Architecture overviewAvailable under NDA
- Business-continuity overviewAvailable under NDA
- Security questionnaire responsesAvailable on request
- Privacy policyPublished
- Vulnerability-disclosure informationAvailable on request
FREQUENTLY ASKED
Security FAQ.
SECURITY REVIEW
Bring BlueKnight
to your security team.
We can support your review with clear answers on architecture, data handling, model providers, access controls and our assurance programme.

