Is this your company?Buyers are checking Knoetic Inc here. Claim knoetic.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Knoetic is an HR/People analytics SaaS platform that provides People teams with analytics and insights on their workforce, recruiting processes, and other key people data.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Other certifications
List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Knoetic Inc SOC 2 compliant?
Knoetic Inc is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Knoetic Inc SOC 2 Type I or Type II?
Knoetic Inc is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Knoetic Inc's SOC 2 for a vendor risk assessment?
Yes. Knoetic Inc's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Knoetic Inc penetration tested?
Knoetic Inc hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Knoetic Inc secure?
Security isn't a single yes/no, but Knoetic Inc is SOC 2 Type II compliant. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Knoetic Inc have a bug bounty or vulnerability disclosure program?
Knoetic Inc hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@knoetic.com or via a /security page (Knoetic Inc lists a security contact).
Who are Knoetic Inc's subprocessors?
Knoetic Inc lists 12 subprocessors on its trust center, including Amazon Web Services, Dagster, Snowflake, Anthropic, Cursor. Buyers use this for fourth-party risk review.
Where does Knoetic Inc host or store data?
Knoetic Inc hosts on AWS, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Knoetic Inc's trust center or security page?
Knoetic Inc's trust center is at https://trust.knoetic.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does Knoetic handle CCPA and GDPR?
Our MSA incorporates language for the CCPA. Should you need a Data Processing Adendum (DPA) for your EU employees, please request that from your Knoetic sales rep and they can send over our Form DPA.
How does Knoetic deploy and maintain its service?
The Knoetic application is hosted on cloud infrastructure provided by Amazon Web Services (AWS). All data storage and computation is conducted in US data centers only. Knoetic hosts, manages, operates and maintains its software for remote electronic access.
How does Knoetic obtain and process client data?
Knoetic builds integrations that interface through APIs and data reports with a client’s core HR systems. These primarily include human resource information system (HRIS) and applicant tracking system (ATS) but can include additional systems upon client request. These integrations are active for as long as the client engagement persists. Knoetic has the ability to delete all client data within 30 days of a client request or upon the termination of a client engagement, whichever comes first.
What company/user data does Knoetic require?
Knoetic’s product requires basic employment data about a client’s employees, including: personal data such as name, job title, and work email address; employment data such as current and historical jobs, current and historical compensations, academic and professional qualifications, area of responsibility. A full-list can be found in the download section. For all data integrations, Knoetic explicitly does not require sensitive employee information such as: ● Social security numbers ● Tax identification numbers ● Emergency contact information ● Credit card or bank account numbers We instruct our clients not to grant access to any fields containing such data, and our data integration processes flag and exclude potentially sensitive employee attributes before they ever hit our servers. Our data classification policy is available on request.
How does Knoetic ensure that customers can only access their own data?
Knoetic uses a multi-tenant architecture that provides efficient and scalable solutions for its clients while maintaining maximum data security and isolation. Client data can only be created, managed, and accessed by authorized representatives. This access control is enforced using role-based permissions as well as application-level checks. Knoetic databases are hosted by Amazon’s Relational Database Service (RDS), with built-in network and application firewalls. Amazon’s data centers are widely recognized for both physical and network security. They are accredited under ISO 27001, SOC 1/SOC 2/SSAE 16/ISAE 3402, PCI Level 1, and Sarbanes-Oxley. Please see AWS security references for more information on the security services provided by these hosts.
How does Knoetic control internally who has access to sensitive data?
Internal access to all Knoetic data and applications is protected by an employee authentication system with role-based permissions. This access is restricted to full-time engineers and support staff. Access is granted using the principle of least privilege. If a Knoetic employee is terminated, they lose access to all internal tools, and their application credentials are revoked. They do not have further access to any internal data, including client data. In addition, we have remote wipe capability for employee devices, and have software installed on all employee machines to enforce best practices such as secure passwords.
Where is data stored, and how is it encrypted?
Knoetic customer data is stored on scalable cloud servers provided by Amazon Web Services. Data is stored in data centers located exclusively in the United States, and accessed solely by US employees. All client data is stored encrypted with 256-bit Advanced Encryption Standard (AES-256). Our data backups are similarly encrypted. All of Knoetic’s products and services are only accessible over a secure HTTPS connection. Knoetic servers use HTTPS with TLS 1.2 for all communications. This includes 128 bit TDES/3DES or equivalent cryptographic algorithms. (All SSLv3 protocols have been disabled.)
How are cryptographic keys managed?
Cryptographic keys are generated using a SHA-256 cryptographic hash function, and managed and stored within isolated cryptographic modules. The key manager (Head of Engineering) is responsible for managing the generation, storage, rotation, export, and retirement of cryptographic keys. Keys are rotated periodically.
How are passwords stored?
Passwords are never stored in or communicated via plaintext - we use a one-way cryptographic hash function called BCrypt, an industry standard for password hashing. And we salt our BCrypt hashes for maximal security (using PBKDF2 and SHA-256, 24000 iterations).
What data points do you typically pull in and how does this data flow once in your environment?
Knoetic typically connects with HR systems via their external APIs with requests for data about each employee. These data points can broadly be grouped into the following categories (you can see a full list of all data fields in our downloads section): ● Employee general information: Name, age, gender, ethnicity, contact information, etc. ● Compensation: Pay amount, rate, frequency, associated dates, etc. ● Employment: Job title, manager, position, tenure, associated dates, etc. ● Recruiting: Applications, candidates, requisitings, recruiters, interviews ● Performance: Rating, comment, description This data is extracted from the underlying systems approximately 4-6 times a day and is stored in our S3 environment. From there our ETL process transforms and loads this data into Knoetic where it is live for you to view on Knoetic.
Does Knoetic support SSO / SAML?
Yes - we support any provider supporting SAML. This includes but is not limited to: Okta, Auth0, Duo and OneLogin.
How Knoetic Uses Google Calendar Data
Knoetic integrates with Google Calendar to support specific user-facing features within the platform. When a user connects their Google Calendar, Knoetic accesses calendar data in read-only mode to display meeting information within the product. This includes event titles, start and end times, and attendee email addresses. Knoetic does not create, modify, or delete calendar events. Knoetic also uses third-party AI providers, including OpenAI, Anthropic (Claude), and Google Gemini, to power certain features within the platform. These AI services are used only for user-initiated workflows. Google Calendar data is not shared with or processed by any AI systems. Calendar data is used only for calendar-related functionality. AI systems operate on separate data pipelines and do not access Google user data. Knoetic does not use Google user data for AI model training, advertising, or any secondary purposes. Data is used only to support features explicitly initiated by the user and is handled in accordance with enterprise-grade security standards, including SOC 2 Type II controls. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.