Trust

Security

What Headknot can see, what it can change, and what leaves it. Including what we have not put in place yet.

What we do not claim

Headknot holds no third-party security certification. We are not SOC 2 audited, not ISO 27001 certified, and we do not hold an independent penetration-test attestation.

We are an early product and would rather tell you that than display a badge that implies otherwise. If a certification is a requirement for you, we are not there yet — say so and we will tell you honestly whether that is likely to change on a timeline that suits you.

Everything below describes what the product actually does today.

We read; we do not write back

Every integration Headknot offers is read-only. It cannot post a message, edit a document, close a ticket, or delete anything in Slack, Notion, Google Drive, Jira, Confluence, GitHub or Linear.

This is a property of the integrations themselves, not a setting you have to find. The worst case for a compromised Headknot account is disclosure of content that account could already read — not modification of your source systems.

You choose what it can see

Nothing is ingested until you connect a source, and you can disconnect any source at any time. Disconnecting stops further ingestion.

Any source, document, or individual item can be marked sensitive. Sensitive material is hidden from workspace members without access and is never used to answer a question, on any plan.

Workspace roles control who can connect sources, who can read what, and who can administer the workspace. On Pro, access can be requested and approved rather than granted by default, and passwords and personal data found in your content are flagged automatically.

What reaches our AI provider

Headknot uses OpenAI to generate search embeddings, extract the people, projects and claims inside your content, resolve different names for the same thing, detect conflicting statements, and answer your questions. Content from your connected sources is sent to OpenAI’s API for those purposes.

Marking something sensitive excludes it from answers and from people without access. It does not retroactively unsend content that was already processed when it was ingested, and we would rather be precise about that than let the control sound stronger than it is. If material must never reach an AI provider at all, do not connect the source that contains it.

One thing is blocked before it leaves: during ingestion, documents are scanned for credentials and secrets, and a document that trips the scanner is not sent to the model. That scan is a safety net rather than a guarantee — if the scanner itself fails, ingestion continues rather than halting, so it should not be relied on as your only control.

OpenAI states that data sent to its API is not used to train or improve OpenAI models unless the customer explicitly opts in. We have not opted in, and we do not train any model of our own on your content.

OpenAI retains API inputs and outputs for up to 30 days for abuse monitoring, unless longer retention is required by law. Zero Data Retention, which would exclude your content from those logs entirely, requires prior approval from OpenAI. We do not hold it, and we are not currently seeking it — so the 30-day window applies to your content today. If that window is the thing standing between you and adopting Headknot, tell us; it is a decision we can revisit, and we would rather hear it than have you assume we already handle it.

Answers can be checked, not just trusted

Every answer cites the specific documents it drew on, so a claim can be verified in a click rather than taken on faith.

When your content does not support an answer, Headknot is designed to say so rather than produce something plausible. Declining is a designed outcome, not a failure.

Facts are stored with the date they were true, so an answer tells you when it stopped being something else instead of quietly returning the newest page.

Infrastructure and access

Data is encrypted in transit with TLS, and at rest by our hosting and database providers.

Business data is scoped to a workspace throughout the system, so one workspace’s content cannot be returned to another.

Authentication is handled by a dedicated identity provider rather than by rolling our own; the browser holds a session cookie, not a token.

Access to production systems is limited to the people who operate the service, and workspace activity is recorded in an activity log you can read.

Reporting a vulnerability

If you believe you have found a security issue, email support@headknot.com with enough detail to reproduce it. We will acknowledge your report and tell you what we intend to do about it.

Please do not run automated scans against production or access data that is not yours while testing. We will not pursue action against good-faith research that respects those limits.