---
title: "Security"
url: "http://35.223.47.52/security/"
date: "2026-08-13T14:43:13+00:00"
modified: "2026-08-24T06:02:36+00:00"
type: "page"
---

# Security

Security &amp; ComplianceData security at Knit
=====================

We hold our policies, practices, and processes to the industry’s highest standards. Knit runs on AWS with a 99.99% uptime SLA, and never stores your end users’ data on its servers.

[Talk to a Human](/book-demo)
[Visit Our Trust Center](https://compliance.getknit.dev/)



How security works at Knit
--------------------------



### Data encryption

All data at Knit is doubly encrypted — at rest with AES-256 and in transit with TLS 1.3. PII and user credentials carry an additional layer of application-level encryption.





### Your data isn’t shared with any third party

Knit acts as a pure passthrough proxy — we don’t store your user data. It’s processed on our application server and sent directly to your webhooks.





### AWS infrastructure, 99.99% uptime

Knit runs on AWS with a fault-tolerant architecture built for high availability, backed by an uptime SLA of up to 99.99%.





### Continuous monitoring

Our infrastructure is monitored around the clock with the finest intrusion detection systems. A 24/7 support team resolves every security issue immediately.





### Regular penetration testing

Knit undergoes regular, independent penetration testing to identify and remediate vulnerabilities before they can be exploited.





### Industry certifications

Knit complies with SOC 2, GDPR, and ISO 27001 — audited standards for security, availability, and data protection.







API &amp; webhook security
--------------------------

Every request to and from Knit is authenticated and verifiable — not just encrypted in transit.



### API authentication

Every API request to Knit requires a Bearer token API key plus an integration identifier header — nothing is accepted without both.





### Verified webhooks

Every webhook Knit sends is signed with an HMAC-SHA256 signature, so you can cryptographically verify it actually came from Knit before you trust it.





[Read the authentication docs](https://developers.getknit.dev/reference/authenticating-your-apis-with-knit)



Data residency &amp; minimization
---------------------------------



### Choose where your data is processed

Knit supports data residency in the US, EU, and India, so you can keep processing in the region your compliance requirements call for.





### Sync only what you need

Sync Filters let you precisely control which fields and records sync from each connected app — instead of pulling everything by default.







Enterprise-grade security
-------------------------

![SOC 2 certified](/wp-content/themes/knit/assets/images/security-logos/soc2.svg)
![GDPR compliant](/wp-content/themes/knit/assets/images/security-logos/gdpr.svg)
![ISO 27001 certified](/wp-content/themes/knit/assets/images/security-logos/iso.png)

[Visit our Security Center](https://compliance.getknit.dev/) [Review the DPA](/dpa)



Put Integrations on Autopilot. Talk to Experts.
-----------------------------------------------

Knit is loved by customers across the globe due to our seamless product and white glove support. You'll love us too!

 [Talk to a Human](/book-demo)
