Home / Security and data handling
Security and data handling

Control starts before an automation runs.

This page describes the current public-site and controlled-pilot security posture. It is not a certification claim. Product security statements expand only as the corresponding controls are implemented and verified.

Current website safeguards

  • HTTPS with HSTS and restrictive browser security headers.
  • Same-origin form intake with server-side validation, size limits, origin checks, rate limits, bot traps, and duplicate handling.
  • Private submission records with limited retention and restricted administrative access.
  • No payment-card or account-password collection through the public pilot form.

Controlled-pilot principles

  • Least-privilege provider connections and revocable authorization.
  • Exact approval for sensitive actions and destinations.
  • Provider read-back for action-bearing execution evidence.
  • Replay suppression, failure containment, recovery records, and immutable version linkage.

Reporting a concern

Email evan@knoxcapture.com. Do not include passwords, access tokens, or sensitive customer data in the first message.