Last Updated: 08/30/2026
Knowhere is an Event Resource Management platform. Customers trust us with their meeting schedules, contacts, and event data. This page describes the controls we have in place today and is updated as they change.
Knowhere is an early-stage company, incorporated in 2025. We do not hold a SOC 2 report. We would rather say that plainly than overstate it. Our infrastructure providers are independently certified, and the controls below are in place now.
Questions or a security questionnaire to complete? Email security@goknowhere.com.
Microsoft Azure (SOC 2, ISO 27001) and Supabase (SOC 2 Type II) host all production systems.
Data processing and confidentiality terms are included in our Master Services Agreement. Where applicable law requires one, we enter into a data processing addendum with the customer (MSA Section 3(c)).
Payment processing is delegated to Stripe, a PCI DSS Level 1 service provider. Card data never reaches Knowhere systems.
| Document | Availability |
|---|---|
| Privacy Policy | Public |
| Terms of Use | Public |
| Master Services Agreement, including Service Level Agreement (Exhibit A) | On request |
| Subprocessor list | Public (below) |
Frontend, server-side compute, and AI features run on Microsoft Azure. Database, authentication, and file storage run on Supabase, hosted on AWS in the US East region.
All customer data is stored and processed in the United States.
All connections use TLS 1.2 or higher. HTTP Strict Transport Security is enforced.
Stored data is encrypted by our infrastructure providers using managed keys.
Transactional email (invitations, confirmations, one-time codes) is sent through Resend, which is SOC 2 Type II certified.
Development and production run on separate infrastructure with separate credentials.
The production database is backed up daily by Supabase. Backups are encrypted and stored in the same region.
We target 99.5% monthly uptime. Full terms in MSA Exhibit A, available on request.
Knowhere is multi-tenant. Every customer's data is isolated with Postgres row-level security. Every table is policy-gated by company, enforced by the database rather than application code.
Sign-in by Google SSO, email one-time code, or password. Passwords are hashed by our auth provider and are never visible to Knowhere staff.
Managers administer the account. Team members see their own schedule and the meetings they are part of.
The application enforces a content security policy and clickjacking protection.
Public booking and RSVP endpoints are rate-limited and bot-protected.
OAuth tokens for connected CRMs are encrypted with AES-256-GCM before storage and are never readable by the browser.
AI runs on OpenAI models hosted inside Knowhere's own Azure tenant. Prompts and data do not leave that tenant and are not used to train the underlying models.
Stripe handles all card processing and storage. Knowhere receives billing metadata only.
We do not sell customer data.
We do not use identifiable customer data to train or improve any third-party AI model or any generalized model for other customers. Aggregated, de-identified usage data may be used to improve the Knowhere service (MSA Sections 4(d) and 8).
For 30 days after an agreement ends, customers can request an export of their data in our standard format. After that window, customer data is deleted under our standard deletion practices (MSA Section 12(c)).
Listed below. The list is updated before any new subprocessor is added.
Limited to founders and engineering.
When support needs to view a customer account, access is granted explicitly, expires after 60 minutes, and is logged.
Every change ships through a reviewed pull request and passes automated typechecking, linting, and tests before merge. Deployment to production is automated from source control.
Security concerns can be reported to security@goknowhere.com. We acknowledge reports within 5 business days.
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Hosting, compute, AI | United States |
| Supabase | Database, authentication, file storage | United States |
| Stripe | Payments | United States |
| Resend | Transactional email | United States |
| Sign-in, maps, bot protection | United States | |
| GrowthBook | Feature flags | United States |
Support runs Monday through Friday, 9am to 6pm Pacific, excluding US holidays.
| Severity | Definition | Target Initial Response |
|---|---|---|
| 1 | Service down or a core feature unusable for all users | 4 business hours |
| 2 | Feature significantly impaired for some users, workaround exists | 1 business day |
| 3 | General questions, minor issues, feature requests | 2 business days |
Targets only. Binding terms in MSA Exhibit A.
For security questions, questionnaires, or document requests, contact us at security@goknowhere.com or by post at:
Cinco AI Inc