Security, Privacy and TrustBuilt Into ExactlyHow
Operational knowledge is one of your organization's most valuable assets. ExactlyHow is designed with layered security, privacy controls and governance features to help protect that information throughout its lifecycle.
Security At A Glance
The foundational controls protecting your operational knowledge.
Encryption
Protect data in transit and at rest using modern encryption standards.
Authentication
Email-verified accounts with optional passkey sign-in. Authenticator-app MFA is coming soon.
Access Control
Role-based permissions ensure users only access what they need.
Private File Storage
Operational documentation and attachments remain protected.
Auditability
Track important actions with activity history and audit capabilities.
Ownership Continuity
Every process keeps a named owner, and ownership transitions with people instead of disappearing.
See it in the product
Role permissions and ownership continuity aren't abstract policies — they're screens in the real workspace.
Security, user management, permissions, and audit logs — one admin workspace
Ownership transitions on record, not lost in an inbox
Our Security Principles
Protect Operational Knowledge
ExactlyHow is designed to preserve institutional knowledge while reducing unnecessary exposure to unauthorized internal or external parties.
Least Privilege
Users receive only the permissions necessary for their responsibilities, enforced through strict role-based access controls.
Transparency
We clearly communicate our implemented controls, planned security improvements, and current compliance status without exaggeration.
Continuous Improvement
Security is never finished. Our defensive posture, tooling, and policies evolve continuously as the platform grows.
Platform Security
Comprehensive controls built directly into the ExactlyHow application to ensure knowledge remains protected and accessible.
Authentication
Passkeys
Optional passwordless sign-in with Face ID, Touch ID, Windows Hello, or a security key. Authenticator-app MFA is coming soon.
Benefit: Mitigates credential theft and phishing.
Session Management
Secure, time-bound authentication tokens.
Benefit: Reduces session hijacking risks.
Password Security
Strong hashing and complexity requirements.
Benefit: Protects against brute force attacks.
Role-Based Permissions
Editor
Can build and maintain operational knowledge.
Benefit: Restricts editing to authorized staff.
Viewer
Can search and read documented processes.
Benefit: Enables safe organization-wide access.
Administrator
Manages organization settings and users.
Benefit: Centralizes security governance.
Organization Isolation
Private Organization Data
Logical separation of customer workspaces.
Benefit: Prevents cross-tenant data leakage.
Secure Storage
Isolated operational knowledge repositories.
Benefit: Maintains data confidentiality.
Monitoring
Application Monitoring
Continuous oversight of platform health.
Benefit: Ensures high availability.
Error Monitoring
Real-time alerting for application exceptions.
Benefit: Accelerates incident response.
Audit History
Immutable logs of administrative actions.
Benefit: Supports compliance reviews.
Subscription Billing
Business checkout and invoices run through Stripe. ExactlyHow stores plan, seat count, and Stripe customer and subscription IDs only.
Benefit: Card numbers are not stored on ExactlyHow servers.
Data Protection Architecture
Customer operational knowledge is protected through layered security controls rather than relying on a single defensive measure.
Privacy Commitments
Customer Data Ownership
Customers retain full ownership and rights to their organizational data. ExactlyHow does not claim ownership of your operational knowledge.
Data Isolation
Each organization's information remains logically separated at the application level to prevent unauthorized access between tenants.
Privacy Commitment
ExactlyHow is committed to handling customer information responsibly and transparently, adhering to modern privacy principles.
Data Requests
Our support team assists enterprise customers with administrative data exports, deletion requests, and account-related privacy inquiries.
Compliance Roadmap
ExactlyHow accurately communicates current certifications and readiness. Compliance claims are updated only after requirements have been satisfied.
Last updated September 2026.
- Modern encryption
- Role-Based Permissions
- Secure Authentication
- Audit History
- Application Monitoring
- Ownership Continuity
- Card payments handled by Stripe
- Security Policies
- Incident Response Procedures
- Internal Security Program
- SOC 2 Type II
- ISO 27001
- GDPR Readiness
- Enterprise Security Reviews
- Vendor Questionnaires
Subprocessors
ExactlyHow carefully evaluates service providers that support delivery of the platform.
Security Documentation
Security Overview
Available upon request.
Architecture Overview
Available upon request.
Incident Response Summary
Available upon request.
Vendor Security Questionnaire
Available upon request.
Penetration Testing Summary
Available when completed.
Compliance Documentation
Shared as certifications become available.
Help Us Improve Security
If you believe you have identified a potential security vulnerability, please contact our security team responsibly so we can investigate and resolve the issue.
Security FAQ
How is customer data protected?
Who owns the uploaded documentation?
Is customer data encrypted?
Can organizations control user permissions?
Do you support Single Sign-On?
How are backups managed?
Can security documentation be requested?
Do you complete vendor security questionnaires?
What certifications are currently available?
Where are payment details stored?
How is operational knowledge protected?
Operational knowledge should stay yours.Isolated, encrypted, and owned by you.
Tenant isolation, encryption, and role-based permissions protect how work is done. Export it any time.