Home / Security and data handling
Security and data handling
Control starts before an automation runs.
This page describes the current public-site and controlled-pilot security posture. It is not a certification claim. Product security statements expand only as the corresponding controls are implemented and verified.
Current website safeguards
- HTTPS with HSTS and restrictive browser security headers.
- Same-origin form intake with server-side validation, size limits, origin checks, rate limits, bot traps, and duplicate handling.
- Private submission records with limited retention and restricted administrative access.
- No payment-card or account-password collection through the public pilot form.
Controlled-pilot principles
- Least-privilege provider connections and revocable authorization.
- Exact approval for sensitive actions and destinations.
- Provider read-back for action-bearing execution evidence.
- Replay suppression, failure containment, recovery records, and immutable version linkage.
Reporting a concern
Email evan@knoxcapture.com. Do not include passwords, access tokens, or sensitive customer data in the first message.