Security & data
Plain answers to the questions a security-conscious buyer asks before signing. No compliance theatre — when we don't hold a certification, we say so.
Where is data stored?
Knurl runs on managed infrastructure in a single region (the hosted plan's default region — ask if you need a specific one). Records and photo blobs are stored in two separate managed services. On Enterprise with the on-prem option, both stores live entirely in your infrastructure and Knurl never sees the data.
Who can access facility data?
Inside Knurl: only users you invite. Tenant access is scoped to your facility on every API call; crossing facility boundaries returns 404. Only multi-site plans expose a cross-facility view, and even there it's scoped to the organisation's membership set.
Inside the operating team: the on-call engineer (currently the founder) has database access for incident response. There is no broad customer-data access for support or sales.
How are devices revoked?
When you remove a technician's device from the dashboard (Team > Devices > Revoke), the device's session is invalidated on the next sync attempt and any queued offline writes from it are rejected. A device that's never online again retains a read-only cache of data already synced, but cannot push new writes and cannot reach data created after the revocation.
How does offline sync work?
The mobile app fully works offline. Every action the technician takes is queued locally. When connectivity returns, photo uploads drain before the actions that reference them — a work-order completion never references a photo that hasn't made it to the server.
If the server rejects a queued action (most often because a manager pre-empted the work order while the device was offline), the rejection is surfaced in the mobile app — but the local data (photos, notes) is preserved. Nothing is silently lost.
What audit trail exists?
Every state change on a work order is an append-only event, timestamped and attributed to the actor. Edits do not overwrite — they create a new event. The current state shown in the dashboard is a projection of the latest event.
Analytics and reports project over the event log, so the numbers in the dashboard are always consistent with what actually happened.
What happens to my data if I stop paying?
After the grace period, the facility becomes read-only. It remains exportable for 180 days, then enters a 90-day pending-deletion window with warnings at T-90, T-30, and T-7 days before deletion. Full details →
At any point in that window, an export from Settings → Export all datagives you a ZIP containing every entity. Your data is yours; there is no “contact us to export” gate.
Implementation posture
Knurl's implementation is designed around signed licenses, scoped tenant access, verified payment webhooks, and append-only event logs. Enterprise buyers can request implementation details during security review — we'll walk through the specifics with your team under NDA rather than publishing internals here.
What certifications exist today?
None. Knurl is too young to have completed SOC 2 Type II, ISO 27001, HIPAA, or any other formal certification. We don't want to misrepresent that.
If your procurement process requires one of those, contact [email protected]with the specific framework — we'll be honest about timelines and what an alternative path looks like (e.g. a custom annex to the contract, or the on-prem option which puts the data under your own compliance scope).
How are security issues reported?
Email [email protected]. We follow RFC 9116 — see knurl.work/.well-known/security.txt for the canonical disclosure policy. We respond within one business day.
What we don't do
- We don't sell or share customer data. No third-party analytics on the dashboard. No targeting pixels. No data brokers.
- We don't use customer data to train models. Your photos and work-order text stay inside your tenant.
- We don't hold a payment card on file. Polar (PCI DSS-compliant) handles all card data. We see only the subscription metadata.
9e39bf7)