Enterprise-grade security, built into every answer.
SOC 2 Type II audited, ISO 27001:2022 certified, GDPR compliant, and your documents are never used to train public AI models.
Independently audited. Continuously monitored.
Verified by third-party auditors and monitored continuously, not just checked at audit time.
SOC 2 Type II
AuditedIndependent audit of our security, availability, and confidentiality controls, operating effectively over time, not just on paper.
ISO 27001:2022
CertifiedThe international standard for information security management, covering how we build, run, and govern the platform.
GDPR
CompliantDocumented DPIAs, an EU representative, and a full inventory of personal data, for teams that operate under European rules.
Defense in depth, audited end to end.
The shape of the program. Every control below is published in full, with its description, in the Trust Center.
Product security
Keeping the platform itself safe to use.
- Annual production system user review
- Documented vulnerability remediation
- Centralized flaw-remediation management
Data security
Protecting, isolating, and governing your information.
- AES-256 encryption at rest
- MFA on critical systems
- Production database access restriction
- Backups with recovery testing
Network security
Guarding traffic and connections at every hop.
- Default-deny firewall on production hosts
- HTTPS / TLS 1.2+ for all transmissions
- Centralized security event logging
App security
Keeping customers informed, surfacing anomalies.
- Continuous monitoring for unauthorized activity
- Conspicuous privacy notice
Endpoint security
Keeping the devices that touch your data clean.
- Anti-malware on all employee endpoints
- Remote-device security validation
- Automatic session lock after 15 min
Corporate security
Governing our people, policies, and vendors.
- Security & privacy training, new-hire and periodic
- Risk assessments & third-party reviews
- CISO & CPO with assigned responsibilities
Three promises about your data.
Plain-language commitments, no fine print.
Your data stays yours.
Your documents are never used to train public AI models, never shared with other customers, and never leave your isolated tenant. Full stop.
You control access.
Role-based permissions decide who sees what, down to specific knowledgeBases. Add, remove, or revoke users in seconds. Every action is logged.
You can leave with everything.
Export your documents and data at any time. If you cancel, we delete your tenant within the timelines defined in your contract. No lock-in.
For your security team.
The specifics your InfoSec and procurement teams will ask about. Forward this page; it is built for that.
| Area | What we run | Detail |
|---|---|---|
| Encryption in transit | TLS 1.2+ | All API and browser traffic encrypted end to end. |
| Encryption at rest | AES-256 | Customer data and backups encrypted with managed keys. |
| Tenancy model | Single-tenant | Logical isolation per customer, data is never co-mingled. |
| Uptime & availability | 99.9% target SLA | Active monitoring, automated failover, documented RTO/RPO. |
| Deployment options | Cloud · air-gapped on-prem | For networks that never touch the public internet. |
| Subprocessors | Published list | Current subprocessors are listed in the Trust Center. |
The current subprocessor list is published in full in the Trust Center, readable without a request, with what each one is used for.
What you can get, and what it takes to get it.
Three tiers, no guessing. Most security reviews only ever need the first two.
Public, right now
Certifications and their status, the six control categories and what is in them, and the full subprocessor list, all readable in the Trust Center without asking anyone.
On request
The SOC 2 Type II report, the ISO 27001 certificate, and any of the 42 policies and documents behind the program. Request access in the Trust Center, or ask us and we will send it.
Under NDA
Penetration-test summaries, architecture detail, and anything your questionnaire needs that is not covered above. We fill in customer security questionnaires, we do not ask you to accept ours instead.
Stuck, or on a deadline? Contact us and say what your reviewer needs, that is faster than working the portal.
The questions security teams ask first.
Is my data used to train AI models?
No. Your documents are never used to train public AI models, never shared with other customers, and never leave your isolated tenant.
How is my data isolated from other customers?
knowledgeXpert runs single-tenant with logical isolation, your data is never co-mingled with anyone else’s. For environments that require it, an air-gapped, on-premises deployment is available.
Can I export my data and leave?
Yes, at any time. If you cancel, we delete your tenant within the timelines defined in your contract. No lock-in.
Where do I get your SOC 2 report and policies?
In the BearCreek AI Trust Center. The certifications, the control categories and the subprocessor list are readable there without asking. The SOC 2 Type II report itself, the ISO 27001 certificate and the 42 underlying policies are released on request, use the Request access button there or contact us and we will send them.
Will you complete our security questionnaire?
Yes. Send it over and we will fill it in rather than pointing you at a portal and asking you to reconcile it yourself. If something in it needs an NDA first, we will say so and start that.
Certifications, controls and subprocessors are readable in the BearCreek AI Trust Center; the audit report and the policies behind them are released on request. Need something specific for procurement? Contact us.
Send this page to your security team, then see it on your own documents.
Thirty minutes, your documents, every answer traced to its source. Your data stays in your tenant.