Skip to content
Security & Trust

Enterprise-grade security, built into every answer.

SOC 2 Type II audited, ISO 27001:2022 certified, GDPR compliant, and your documents are never used to train public AI models.

SOC 2 Type IIISO 27001:2022GDPRAir-gapped / on-prem available
Certifications & frameworks

Independently audited. Continuously monitored.

Verified by third-party auditors and monitored continuously, not just checked at audit time.

SOC 2 Type II

Audited

Independent audit of our security, availability, and confidentiality controls, operating effectively over time, not just on paper.

ISO 27001:2022

Certified

The international standard for information security management, covering how we build, run, and govern the platform.

GDPR

Compliant

Documented DPIAs, an EU representative, and a full inventory of personal data, for teams that operate under European rules.

48 published controls · 6 categories

Defense in depth, audited end to end.

The shape of the program. Every control below is published in full, with its description, in the Trust Center.

Product security

Keeping the platform itself safe to use.

  • Annual production system user review
  • Documented vulnerability remediation
  • Centralized flaw-remediation management

Data security

Protecting, isolating, and governing your information.

  • AES-256 encryption at rest
  • MFA on critical systems
  • Production database access restriction
  • Backups with recovery testing

Network security

Guarding traffic and connections at every hop.

  • Default-deny firewall on production hosts
  • HTTPS / TLS 1.2+ for all transmissions
  • Centralized security event logging

App security

Keeping customers informed, surfacing anomalies.

  • Continuous monitoring for unauthorized activity
  • Conspicuous privacy notice

Endpoint security

Keeping the devices that touch your data clean.

  • Anti-malware on all employee endpoints
  • Remote-device security validation
  • Automatic session lock after 15 min

Corporate security

Governing our people, policies, and vendors.

  • Security & privacy training, new-hire and periodic
  • Risk assessments & third-party reviews
  • CISO & CPO with assigned responsibilities
Our data principles

Three promises about your data.

Plain-language commitments, no fine print.

Promise 01

Your data stays yours.

Your documents are never used to train public AI models, never shared with other customers, and never leave your isolated tenant. Full stop.

Promise 02

You control access.

Role-based permissions decide who sees what, down to specific knowledgeBases. Add, remove, or revoke users in seconds. Every action is logged.

Promise 03

You can leave with everything.

Export your documents and data at any time. If you cancel, we delete your tenant within the timelines defined in your contract. No lock-in.

Technical snapshot

For your security team.

The specifics your InfoSec and procurement teams will ask about. Forward this page; it is built for that.

Technical security snapshot
Area What we run Detail
Encryption in transit TLS 1.2+ All API and browser traffic encrypted end to end.
Encryption at rest AES-256 Customer data and backups encrypted with managed keys.
Tenancy model Single-tenant Logical isolation per customer, data is never co-mingled.
Uptime & availability 99.9% target SLA Active monitoring, automated failover, documented RTO/RPO.
Deployment options Cloud · air-gapped on-prem For networks that never touch the public internet.
Subprocessors Published list Current subprocessors are listed in the Trust Center.

The current subprocessor list is published in full in the Trust Center, readable without a request, with what each one is used for.

For your procurement process

What you can get, and what it takes to get it.

Three tiers, no guessing. Most security reviews only ever need the first two.

Public, right now

Certifications and their status, the six control categories and what is in them, and the full subprocessor list, all readable in the Trust Center without asking anyone.

Timing No request needed

On request

The SOC 2 Type II report, the ISO 27001 certificate, and any of the 42 policies and documents behind the program. Request access in the Trust Center, or ask us and we will send it.

Timing Same business day, in practice

Under NDA

Penetration-test summaries, architecture detail, and anything your questionnaire needs that is not covered above. We fill in customer security questionnaires, we do not ask you to accept ours instead.

Timing Ask and we will start the paperwork

Stuck, or on a deadline? Contact us and say what your reviewer needs, that is faster than working the portal.

Security FAQ

The questions security teams ask first.

Is my data used to train AI models?

No. Your documents are never used to train public AI models, never shared with other customers, and never leave your isolated tenant.

How is my data isolated from other customers?

knowledgeXpert runs single-tenant with logical isolation, your data is never co-mingled with anyone else’s. For environments that require it, an air-gapped, on-premises deployment is available.

Can I export my data and leave?

Yes, at any time. If you cancel, we delete your tenant within the timelines defined in your contract. No lock-in.

Where do I get your SOC 2 report and policies?

In the BearCreek AI Trust Center. The certifications, the control categories and the subprocessor list are readable there without asking. The SOC 2 Type II report itself, the ISO 27001 certificate and the 42 underlying policies are released on request, use the Request access button there or contact us and we will send them.

Will you complete our security questionnaire?

Yes. Send it over and we will fill it in rather than pointing you at a portal and asking you to reconcile it yourself. If something in it needs an NDA first, we will say so and start that.

Certifications, controls and subprocessors are readable in the BearCreek AI Trust Center; the audit report and the policies behind them are released on request. Need something specific for procurement? Contact us.

Security review coming up?

Send this page to your security team, then see it on your own documents.

Thirty minutes, your documents, every answer traced to its source. Your data stays in your tenant.