Trust

Security designed for sensitive deal work

Last updated: 1 August 2026

BlueKnight supports research and analysis undertaken by M&A advisors, investment banks, private equity firms and corporate development teams. We recognise that this work can involve commercially sensitive information. Security and responsible data handling are therefore considered throughout the design and operation of our platform.

01 — Encryption

Protection in transit and at rest

BlueKnight uses encryption to help protect customer data while it is transmitted between supported systems and while it is stored. Encryption forms one part of a broader set of technical and organisational measures designed to reduce the risk of unauthorised access, disclosure, alteration or loss.

02 — Data isolation

Customer information remains separated

BlueKnight is designed to keep each customer’s proprietary information logically separated from that of other customers. Customers are not permitted to access, query or benefit from another customer’s confidential mandate information, uploaded documents or private outputs.

03 — Access control

Access is limited to authorised users

Access to the platform is controlled through authenticated accounts and permissions. Access to customer information by BlueKnight personnel is limited to authorised individuals who require it to operate, support, secure or maintain the service.

Where enabled for a customer’s configuration, additional identity and access capabilities may include role-based permissions, single sign-on and administrative activity records.

Customers are responsible for maintaining the confidentiality of their account credentials and for promptly removing access that is no longer required.

04 — Customer data and model training

Raw customer data is not model training material

BlueKnight does not use a customer’s raw confidential data, uploaded documents, mandates or proprietary outputs to train or fine-tune general-purpose AI models unless the customer has expressly agreed to this in writing.

BlueKnight may use aggregated or de-identified operational information to understand service performance and improve the platform, provided that the information does not identify a customer or reveal its confidential information.

05 — Responsible AI processing

Purpose-limited use of AI services

Where AI technology is used to provide a requested feature, BlueKnight seeks to limit the information processed to what is reasonably required for that purpose. Third-party service providers are subject to contractual, confidentiality and data-protection requirements appropriate to the services they provide.

AI-generated research, classifications and recommendations can contain errors or omissions. BlueKnight’s outputs are designed to support professional analysis and should be reviewed by suitably qualified users before being relied upon.

06 — Monitoring and incident response

Prepared to identify and respond

BlueKnight maintains operational processes intended to identify security issues, investigate suspected incidents and take proportionate corrective action. Where a personal-data breach creates a legal notification obligation, BlueKnight will follow the applicable notification requirements.

Customers should report suspected security issues promptly to info@blueknight.io. Please do not include sensitive credentials or confidential mandate information in an initial report.

07 — Resilience

Continuity and recovery

BlueKnight considers service resilience, backup and recovery as part of its operational security programme. No online service can promise uninterrupted availability, but BlueKnight works to reduce avoidable disruption and restore affected services following an incident.

08 — Suppliers and subprocessors

Controlled use of specialist providers

BlueKnight uses selected service providers to help host, maintain, secure and operate the platform. Providers are given access only where reasonably necessary for their role and are subject to appropriate contractual obligations.

Information about relevant subprocessors and international data-transfer safeguards can be made available to customers where required by their agreement or applicable data-protection law.

09 — Security assurance

Transparent procurement support

Security and compliance requirements vary between firms. BlueKnight can discuss its current controls, policies, architecture and assurance programme as part of a customer’s procurement or due-diligence process, subject to appropriate confidentiality protections.

Contact

Security questions

For security enquiries, procurement questionnaires or to report a suspected vulnerability, contact:

info@blueknight.io

Contact BlueKnight