Security & compliance
Built for enterprise standards.
KnownForge holds the keys to your Salesforce orgs, so security is the foundation, not a feature. Controls are designed against the FedRAMP Moderate baseline, hosted entirely on AWS, and every deployment is on the record.
01 / Controls
The spec sheet.
| Area | Control | Detail | Status |
|---|---|---|---|
| Framework | FedRAMP-aligned controls | Designed with the FedRAMP Moderate baseline in mind: access management, audit logging and data protection, built in from day one. | Aligned |
| Attestation | SOC 2 Type II | Audit preparation in progress. | In progress |
| Encryption | AES-256 at rest · TLS 1.2+ in transit | All data encrypted at rest and in transit. | In place |
| Credentials | Fernet-encrypted OAuth tokens | Salesforce, Git and ticketing tokens are stored encrypted per tenant — never in plaintext. | In place |
| Access | Per-tenant RBAC | Role-based access control, scoped to each tenant. | In place |
| Sessions | Inactivity lock · absolute session ceiling | 15-minute inactivity timeout (AC-11) and a 12-hour absolute session limit (AC-12), with a warning before sign-out. | In place |
| Audit | Full deployment audit log | Every deployment action, by every user, recorded. | In place |
02 / Infrastructure
Hosted entirely on AWS.
- Region
- us-east-1
- Database
- Encrypted RDS PostgreSQL
- Network
- Private subnets — no public database access
- Access
- IAM role-based access
03 / Salesforce connection
OAuth 2.0 with PKCE. Tokens never plaintext.
Orgs connect through OAuth 2.0 with PKCE, and the resulting tokens are encrypted before they are stored.
Salesforce org
- OAuth 2.0 + PKCE
- Token-based connection
KnownForge · us-east-1
- IAM role-based access
- Fernet-encrypted tokens
- Per-tenant RBAC
RDS PostgreSQL
- Encrypted at rest (AES-256)
- No public access
04 / Contact
Questions from your security team?
We'll walk them through the controls, the architecture and the audit trail.