Data security at Knit
We hold our policies, practices, and processes to the industry’s highest standards. Knit runs on AWS with a 99.99% uptime SLA, and never stores your end users’ data on its servers.
How security works at Knit
Data encryption
All data at Knit is doubly encrypted — at rest with AES-256 and in transit with TLS 1.3. PII and user credentials carry an additional layer of application-level encryption.
Your data isn’t shared with any third party
Knit acts as a pure passthrough proxy — we don’t store your user data. It’s processed on our application server and sent directly to your webhooks.
AWS infrastructure, 99.99% uptime
Knit runs on AWS with a fault-tolerant architecture built for high availability, backed by an uptime SLA of up to 99.99%.
Continuous monitoring
Our infrastructure is monitored around the clock with the finest intrusion detection systems. A 24/7 support team resolves every security issue immediately.
Regular penetration testing
Knit undergoes regular, independent penetration testing to identify and remediate vulnerabilities before they can be exploited.
Industry certifications
Knit complies with SOC 2, GDPR, and ISO 27001 — audited standards for security, availability, and data protection.
API & webhook security
Every request to and from Knit is authenticated and verifiable — not just encrypted in transit.
API authentication
Every API request to Knit requires a Bearer token API key plus an integration identifier header — nothing is accepted without both.
Verified webhooks
Every webhook Knit sends is signed with an HMAC-SHA256 signature, so you can cryptographically verify it actually came from Knit before you trust it.
Data residency & minimization
Choose where your data is processed
Knit supports data residency in the US, EU, and India, so you can keep processing in the region your compliance requirements call for.
Sync only what you need
Sync Filters let you precisely control which fields and records sync from each connected app — instead of pulling everything by default.