Security & privacy
How Knovas protects your documents, and what it stores.
Your data is kept separate
Every customer has a private space. Your certificate decides which space a request can reach, so it is not possible to read or change another customer’s documents, even by mistake. When you ask for something that is not yours, Knovas answers as if it did not exist.
Only you can read your documents
Knovas employees never access your documents. Only you and your software can read them, and we make absolutely sure that no one else ever will, including anyone at Knovas.
Only your software gets in
Every request that touches your documents must carry a valid certificate issued by Knovas. There are no passwords to guess or leak. Certificates can be withdrawn at any time, and they expire automatically.
Control inside your organisation
With access control you decide which of your own users may see which documents, for example keeping HR files away from everyone outside HR. Documents a user may not see are treated as if they did not exist.
Encrypted in transit and at rest
All traffic between your software and Knovas is encrypted. Your data is also encrypted where it is stored.
What Knovas stores
| What | Stored? |
|---|---|
| The text you upload | Yes. It is needed to search it. |
| Search data derived from your text | Yes, in your private space. |
| Your search questions | Not as text. Only an abstract form of the question and basic information such as length and time. |
| Feedback | Yes, without any personal data about your users. |
| Usage counts | Yes, for billing. They never contain document contents. |
Hosted in Switzerland
Documents, search data and AI processing are in data centres in Switzerland: Microsoft Azure (Switzerland North region, Zurich) and cloudscale in Lupfig. Knovas GmbH is a Swiss company and subject to the Swiss Data Protection Act.
No outside AI providers
All AI features run on models Knovas operates itself on servers in Switzerland. Your documents never go to outside AI providers and are not used to train models.
Your part
- Keep your private key in a secrets manager. Never put it in code or email.
- Create your own key before going live.
- Renew certificates before they expire, and tell us immediately if a key may have been exposed.
- If you use access control, make sure your software sends the right groups for each user.
Deleting your data
You can delete single documents or all of them at any time. See Manage documents. For full account closure, contact us.
Legal
Knovas is built in Zurich and designed for the Swiss Data Protection Act (DSG) and the GDPR. See our Privacy Policy and Terms of Service. For a data processing agreement or security questionnaire, write to contact@knovas.ch.
Questions? Write to contact@knovas.ch.
This page describes Knovas 1.3.0. Last updated .