Security & Trust
Version 2.0
Effective Date: July 9, 2026
Last Updated: July 9, 2026
Our Commitment
We believe security and privacy should be considered at every stage of building KNAPTON, not applied afterward. That means designing features with protection in mind from the start, being thoughtful stewards of the information your organization trusts us with, and treating your data with the same care we would want for our own.
Security is never finished. We continually review, test, and improve our practices as KNAPTON evolves, so that your organization's trust is something we keep earning.
Protecting Your Organization
Every organization on KNAPTON Nexus Hub operates in its own private workspace. Your staff records, schedules, training history, and certificates are never visible to another organization.
Within your workspace, administrators control who can see and do what. Roles and permissions are fully configurable, so a staff member only has access to what their role requires. Administrators can also grant individual staff members additional permissions when needed, without changing anyone else's access.
KNAPTON also separates platform level administration from your organization's own administrators. Your business administrators manage your workspace. They do not have access to platform wide tools, and platform staff do not manage your day to day settings.
Onboarding new staff is handled through a secure invitation process. Invitations are tied to a specific email address, expire automatically, and can be cancelled by your administrators at any time.
Account & Access Security
Passwords are never stored in a way that anyone, including KNAPTON staff, can read them. Only the account holder knows their password.
For added protection, KNAPTON supports a Security PIN that can be required before sensitive actions are taken within a workspace. This gives organizations an extra layer of confidence beyond a standard login.
If a password or Security PIN needs to be reset, the process requires verifying the identity of the person making the request before any change is allowed. Reset codes are single use, time limited, and delivered securely.
These protections work together to reduce the risk of unauthorized account access, whether from a lost password or an attempt by someone outside your organization.
Protecting Your Data
All communication between your browser and KNAPTON is encrypted using HTTPS, so information cannot be intercepted or read while in transit.
Data stored by KNAPTON is protected using the encryption and security safeguards provided by our infrastructure partners.
Files that your organization uploads, such as documents and images, are stored using private storage with controlled, time limited access rather than open public links.
Passwords are never stored as plain text. They are protected using one way encryption methods that cannot be reversed, even by KNAPTON.
Administrative Security & Accountability
Important administrative actions within KNAPTON, such as changes to user access or account settings, are recorded in an audit trail. This helps your organization maintain accountability and supports internal review when needed.
When KNAPTON support staff need to access a workspace to help resolve an issue, that access is logged and limited to what is necessary. Support access is never used to browse customer data without a reason.
Security decisions, such as who is allowed to view or change information, are enforced by KNAPTON's systems rather than left to individual devices or browsers. This means access rules are consistently applied no matter how someone connects to the platform.
Access to platform level administrative capabilities is tightly controlled and kept separate from everyday business administration.
Billing & Subscription Security
Subscription billing and payment processing for KNAPTON are handled through Stripe, a widely trusted payment platform used by businesses around the world. This helps ensure that payment information and billing activity are managed securely and reliably.
Shared Responsibility
Keeping your workspace secure is a partnership between your organization and KNAPTON.
Your organization can help by:
- Using strong, unique passwords
- Keeping Security PINs confidential
- Assigning permissions thoughtfully
- Removing access promptly when staff leave
- Keeping contact information up to date
KNAPTON will:
- Continuously improve our security practices
- Monitor for and respond to potential issues
- Protect the information you entrust to us
- Strengthen platform safeguards over time
Continuous Improvement
Security is an ongoing process, not a one time project. We regularly review and strengthen KNAPTON's security, privacy, and administrative safeguards as the platform grows and as new best practices emerge. Material changes that affect how we protect your data will be communicated to affected customers.
Questions About Security?
If your organization, IT department, or procurement team has questions about KNAPTON's security practices, or if you believe you have discovered a potential security vulnerability, please reach out through our Contact page.
We ask that potential vulnerabilities be reported to us privately, giving us a reasonable opportunity to investigate and respond before any public disclosure. We take every report seriously and respond as quickly as we reasonably can.
For details on how we collect, use, and protect personal information, please review our Privacy Policy.
