Architecture and hosting
KnockAtlas runs entirely on Cloudflare: Workers for application code, D1 for the relational store, R2 for lead media and backups, and KV for session and rate-limit caching. There is no separate application server, VM, or container to patch, and the platform beneath the application maintains SOC 2 Type II and ISO 27001 attestations.
- Data is resident in the United States.
- The application makes no third-party requests. There are no analytics scripts, no trackers, no advertising pixels, and no external font or CDN dependencies — every asset is served from our own origin under a strict Content-Security-Policy.
- Administrative access to the platform is protected by Cloudflare Access with one-time-passcode verification, restricted to named accounts.
Encryption
- In transit: TLS 1.3. HTTP Strict Transport Security is enforced.
- At rest: platform-level encryption across D1, R2, and KV.
- Passwords: PBKDF2-HMAC-SHA-256, 100,000 iterations, with a per-user random salt. Passwords are never stored or logged in any recoverable form.
Tenant isolation
Every query that touches customer data is scoped by organisation identifier, and that scoping is applied in one place rather than repeated per route — so a new endpoint inherits the boundary instead of having to remember it. Role scoping sits on top: a rep sees their own book, a manager their team, a director their region.
The boundary is exercised, not assumed: adversarial tests that attempt cross-organisation reads and writes run as part of an ongoing security review programme, and the isolation model is documented for customer security teams on request.
Identity and access
| Capability | Status |
|---|---|
| Email and password authentication, PBKDF2-hashed | Available today |
| Role-based access: rep, manager, director, organisation owner | Available today |
| Bot protection on sign-in and invitation acceptance | Available today |
| Administrative sessions expire in 24 hours; step-up re-authentication on destructive actions | Available today |
| Sign-in alerting on administrative accounts | Available today |
| TOTP multi-factor for director and administrator roles | In development |
| SAML 2.0 and OIDC single sign-on, with SCIM provisioning and deprovisioning | Committed as a condition of any enterprise pilot, before the first employee account is created. Scoped against Microsoft Entra ID. |
We do not expect an enterprise to federate its workforce into a password database, and we are not asking anyone to.
Independent assurance
- Independent penetration testing precedes any enterprise pilot. The report and remediation summary are shared with your security team under NDA.
- A SOC 2 examination of the application layer is on the company roadmap. In the interim, this page, the Security Overview, the exportable audit trail, and restore-drill evidence are available to evaluators.
- Security questionnaires are answered directly and completely. Send them to security@knockatlas.com — no call required first, five business days.
Audit logging
Administrative and data-affecting actions are recorded to an append-only audit log: lead imports, territory and ZIP assignment, role changes, invitations, exports, and control-plane operations. Each entry carries the actor, the organisation, the action, and a timestamp.
- Retention is 400 days for material events and 45 days for high-volume routine events, swept nightly.
- The log is exportable.
Location data
KnockAtlas records position only at the moment a representative logs a door outcome. It does not track between doors, does not run a background location service, and produces no movement trail.
| Field | Purpose |
|---|---|
| Latitude and longitude at disposition | Confirms the knock happened at the address it was recorded against |
| Timestamp | Orders activity and supports rhythm analytics |
| Reported accuracy radius | Distinguishes a confident fix from a poor one rather than discarding it |
Position is visible to the representative who recorded it and to their management chain. It is not exposed between peers, and managers themselves are not location-tracked by the product.
Deletion and portability
- Export at any time. Full CSV export of leads, dispositions, activity, and assignment — no request, no ticket, no fee.
- On termination, a final export is produced and the organisation's data is purged within 30 days.
- Before any purge, an automatic snapshot is taken and retained briefly so an accidental deletion is recoverable, then destroyed on schedule.
- Backups are encrypted, stored in R2, verified after write, and exercised by a restore drill rather than assumed to work.
Sub-processors
Two, and we will give 30 days' written notice before adding a third.
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Application hosting, database, object storage, CDN, access control | United States |
| Resend | Transactional email — invitations, password resets, security alerts | United States |
Deployment
KnockAtlas installs from the browser. There is no app-store distribution and no mobile device management enrolment, so putting it on a managed device estate requires no action from your endpoint team. Details are in the IT Deployment Brief below.
Evaluation documents
The full Security Overview and IT Deployment Brief are provided to evaluating organisations on request — they are confidential documents, handled the way we handle everything else. Write to security@knockatlas.com and they are sent the same business day, no call required. Role manuals are provided during onboarding and inside the application.