Trust
We hold ourselves to the standard we sell.
KnightGrid exists because an approval without evidence is not a decision. That applies to us as well. This page sets out what we have in place, what we state but haven’t had independently verified, and what we don’t have yet.
Last reviewed 24 September 2026 · Version 1.0
How to read this page
Every statement below carries one of three labels:
- Verified
- Checked by an independent third party. Evidence available on request.
- Attested
- Our own statement. Supporting evidence available on request, but not independently audited.
- Planned
- Not in place today. Target date given when known.
At the time of writing, nothing on this page is independently verified. That will change, and this page will record when it does.
Who we are
KnightGrid is at pre-launch stage. The platform is in alpha.
Your data
What we hold. Vendor evidence documents, assessment responses, Decision Records, and account details for your users.
Each customer’s data is logically separated from every other customer’s.
Customer data is not used to train or improve AI or machine-learning models.
Access
Multi-factor authentication is enforced for all access to production systems.
Actions taken with privileged access are logged.
The integrity of a Decision Record
This is the part of KnightGrid that has to be trustworthy by design, not by policy.
The same inputs produce the same output. A decision can be reproduced from its record.
Every Decision Record is timestamped and sealed with a SHA-256 hash. Any change after sealing is detectable.
No record is sealed without a named person’s sign-off.
Auditors receive their own read-only access. They see what the approver saw.
Change a single character. The seal will not match. This is an illustrative browser demonstration, not a live customer Decision Record.
Incidents and disclosure
To report a vulnerability, email us at security@knightgrid.com
Continuity and exit
Backup schedules, tested recovery objectives, deletion periods and export formats will be published when they can be supported with evidence.
What we don’t have yet
SOC 2 Type II or ISO 27001 certification. Target: not yet scheduled.
An independent penetration test. Target: not yet scheduled.
We have no operating history. You should weight our attestations with that in mind. We would advise the same for any vendor at our stage.
Change log
v1.0 — First publication.
Ask us for the evidence.
Any statement on this page marked ATTESTED can be backed with documentation on request.
