1. Payments
- Card checkout is handled by Paystack.
- We do not store full card pan/CVV on getknown systems.
- We receive payment status, references, and subscription identifiers needed to provision access.
2. Transport
Product and marketing hosts are served over HTTPS/TLS. Browsers should show a secure connection on our production hostnames.
3. Access
- Operational access to production systems is limited to people who need it to run the service.
- Secrets (API keys, payment keys) are stored outside public repositories with restricted file permissions on our ops hosts.
- Customer-facing demos use gated access rather than a public browseable directory of businesses.
4. Application data
- Chat and lead data are processed to provide the assistant and deliver leads to the customer.
- We apply retention and abuse controls appropriate to a small SaaS; customers should export or record important leads in their own systems.
5. Subprocessors (examples)
- Paystack — payments
- Cloud hosting / edge providers used to serve the site and app
- Email delivery for transactional and approved messages
See the Privacy Policy for the fuller picture.
6. Incident contact
If you believe you’ve found a security issue, email hello@getknown.ai with details. Please avoid public disclosure until we’ve had a reasonable chance to respond.
7. What we don’t claim
We don’t flash fake compliance badges. If we publish a formal certification later, it will be named here with scope.