Trust & Security

Security we built first, not bolted on.

knktr handles the data any business worries about most — call recordings, transcripts, and PII. We made the hard decisions before we had customers asking, because retrofitting security is slow, expensive, and loses deals. Here's exactly what we've built.

  • Data residencySydney, Australia
  • EncryptionAES-256 · TLS 1.3
  • Essential EightTarget Maturity Level 2, Q3 2026
  • SOC 2 Type IIIn progress · target Q1 2027
  • Privacy Act 1988Compliant by design
  • Outbound callsACMA-compliant engine

Your data stays in Australia

All knktr.ai customer data is stored and processed in Australia, in Sydney data centres. Not the US. Not Ireland. Not “the cloud” somewhere vague. Sydney — by default, always.

We follow the ACSC Essential Eight

We track formally against the Australian Cyber Security Centre's baseline framework and are targeting Maturity Level 2 by Q3 2026. It's how we build and assess our controls — not a checkbox.

Encryption, done properly

AES-256 at rest, TLS 1.3 in transit. There is no plaintext path for your customer data anywhere in the system.

Your data is yours alone

Each client has strict data isolation. Your recordings, transcripts and customer data never touch another client's AI instance or store — enforced at the infrastructure level, not just by policy.

PII redacted from transcripts

Every transcript runs through automated safety checks that detect and redact personal information before it's stored or surfaced in analytics.

We don't train AI on your data

Your conversations are yours. They're not used to train models or shared with AI providers for training. The systems we use process and discard — they don't retain and learn.

SOC 2 Type II in progress

We're on the SOC 2 Type II path, targeting certification for Q1 2027 — building the controls now so you're not waiting on a questionnaire in two years.

Your data, your call

You're never locked in. Export your recordings, transcripts and configurations in standard formats at any time, and when you offboard we handle your data in line with the retention and compliance requirements that apply to you — confirmed with you in writing.

Privacy Act compliant by design

Built to meet the Australian Privacy Principles under the Privacy Act 1988: we collect only what's needed, tell callers their calls are recorded, and handle access and correction requests within 30 days.

Straight answers

The questions procurement always asks.

Ask us anything else — we're happy to complete a security questionnaire or share our documentation with your team.

Where is my data stored?

All customer data — recordings, transcripts, analytics — is stored and processed in Australia, in Sydney data centres. That includes the AI: every model call and safety check runs in Australia. No customer data is stored or processed outside Australia.

Do you train your AI on my data?

No. Your customer conversations are not used to train models, and we don't share them with AI providers for training. The AI is configured for inference only — it processes calls and discards the input.

What happens to my data if I cancel?

Your data is yours. You can export it in standard formats at any time. When you offboard, we handle your data in line with the retention and compliance requirements that apply to you, and confirm the specifics with you in writing.

Do you comply with ACMA rules for outbound calls?

Yes. Our outbound engine checks the Do Not Call Register before proactive dials, enforces calling hours at the system level, discloses that the caller is an AI, honours opt-outs, and logs consent for every call.

Bring your security checklist.

We'll walk through exactly how your customers' data is handled — on a live demo.