KnightGrid

Trust

We hold ourselves to the standard we sell.

KnightGrid exists because an approval without evidence is not a decision. That applies to us as well. This page sets out what we have in place, what we state but haven’t had independently verified, and what we don’t have yet.

Last reviewed 24 September 2026 · Version 1.0

Our standard of evidence

How to read this page

Every statement below carries one of three labels:

Verified
Checked by an independent third party. Evidence available on request.
Attested
Our own statement. Supporting evidence available on request, but not independently audited.
Planned
Not in place today. Target date given when known.

At the time of writing, nothing on this page is independently verified. That will change, and this page will record when it does.

01 / Who we are

Who we are

Attested

KnightGrid is at pre-launch stage. The platform is in alpha.

02 / Your data

Your data

What we hold. Vendor evidence documents, assessment responses, Decision Records, and account details for your users.

Attested

Each customer’s data is logically separated from every other customer’s.

Attested

Customer data is not used to train or improve AI or machine-learning models.

03 / Access

Access

Attested

Multi-factor authentication is enforced for all access to production systems.

Attested

Actions taken with privileged access are logged.

04 / Decision integrity

The integrity of a Decision Record

This is the part of KnightGrid that has to be trustworthy by design, not by policy.

Attested

The same inputs produce the same output. A decision can be reproduced from its record.

Attested

Every Decision Record is timestamped and sealed with a SHA-256 hash. Any change after sealing is detectable.

Attested

No record is sealed without a named person’s sign-off.

Attested

Auditors receive their own read-only access. They see what the approver saw.

Decision Record · Integrity check
Try the seal
SealedMatches the sealed record.

Change a single character. The seal will not match. This is an illustrative browser demonstration, not a live customer Decision Record.

05 / Disclosure

Incidents and disclosure

To report a vulnerability, email us at security@knightgrid.com

06 / Exit

Continuity and exit

Backup schedules, tested recovery objectives, deletion periods and export formats will be published when they can be supported with evidence.

07 / Limits

What we don’t have yet

Planned

SOC 2 Type II or ISO 27001 certification. Target: not yet scheduled.

Planned

An independent penetration test. Target: not yet scheduled.

We have no operating history. You should weight our attestations with that in mind. We would advise the same for any vendor at our stage.

08 / History

Change log

v1.0 — First publication.

Ask us for the evidence.

Any statement on this page marked ATTESTED can be backed with documentation on request.