Trust
Security designed for sensitive deal work
Last updated: 1 August 2026
BlueKnight supports research and analysis undertaken by M&A advisors, investment banks, private equity firms and corporate development teams. We recognise that this work can involve commercially sensitive information. Security and responsible data handling are therefore considered throughout the design and operation of our platform.
01 — Encryption
Protection in transit and at rest
BlueKnight uses encryption to help protect customer data while it is transmitted between supported systems and while it is stored. Encryption forms one part of a broader set of technical and organisational measures designed to reduce the risk of unauthorised access, disclosure, alteration or loss.
02 — Data isolation
Customer information remains separated
BlueKnight is designed to keep each customer’s proprietary information logically separated from that of other customers. Customers are not permitted to access, query or benefit from another customer’s confidential mandate information, uploaded documents or private outputs.
03 — Access control
Access is limited to authorised users
Access to the platform is controlled through authenticated accounts and permissions. Access to customer information by BlueKnight personnel is limited to authorised individuals who require it to operate, support, secure or maintain the service.
Where enabled for a customer’s configuration, additional identity and access capabilities may include role-based permissions, single sign-on and administrative activity records.
Customers are responsible for maintaining the confidentiality of their account credentials and for promptly removing access that is no longer required.
04 — Customer data and model training
Raw customer data is not model training material
BlueKnight does not use a customer’s raw confidential data, uploaded documents, mandates or proprietary outputs to train or fine-tune general-purpose AI models unless the customer has expressly agreed to this in writing.
BlueKnight may use aggregated or de-identified operational information to understand service performance and improve the platform, provided that the information does not identify a customer or reveal its confidential information.
05 — Responsible AI processing
Purpose-limited use of AI services
Where AI technology is used to provide a requested feature, BlueKnight seeks to limit the information processed to what is reasonably required for that purpose. Third-party service providers are subject to contractual, confidentiality and data-protection requirements appropriate to the services they provide.
AI-generated research, classifications and recommendations can contain errors or omissions. BlueKnight’s outputs are designed to support professional analysis and should be reviewed by suitably qualified users before being relied upon.
06 — Monitoring and incident response
Prepared to identify and respond
BlueKnight maintains operational processes intended to identify security issues, investigate suspected incidents and take proportionate corrective action. Where a personal-data breach creates a legal notification obligation, BlueKnight will follow the applicable notification requirements.
Customers should report suspected security issues promptly to info@blueknight.io. Please do not include sensitive credentials or confidential mandate information in an initial report.
07 — Resilience
Continuity and recovery
BlueKnight considers service resilience, backup and recovery as part of its operational security programme. No online service can promise uninterrupted availability, but BlueKnight works to reduce avoidable disruption and restore affected services following an incident.
08 — Suppliers and subprocessors
Controlled use of specialist providers
BlueKnight uses selected service providers to help host, maintain, secure and operate the platform. Providers are given access only where reasonably necessary for their role and are subject to appropriate contractual obligations.
Information about relevant subprocessors and international data-transfer safeguards can be made available to customers where required by their agreement or applicable data-protection law.
09 — Security assurance
Transparent procurement support
Security and compliance requirements vary between firms. BlueKnight can discuss its current controls, policies, architecture and assurance programme as part of a customer’s procurement or due-diligence process, subject to appropriate confidentiality protections.
Contact
Security questions
For security enquiries, procurement questionnaires or to report a suspected vulnerability, contact:
