ExactlyHow Trust Center

Security, Privacy and TrustBuilt Into ExactlyHow

Operational knowledge is one of your organization's most valuable assets. ExactlyHow is designed with layered security, privacy controls and governance features to help protect that information throughout its lifecycle.

Privacy & Legal
Knowledge Lifecycle Security
Employees
Processes
Encrypted Storage
Search
Permissions
Business Continuity

Security At A Glance

The foundational controls protecting your operational knowledge.

Encryption

Protect data in transit and at rest using modern encryption standards.

Business ValueSafeguard sensitive intellectual property.

Authentication

Secure account authentication with support for multi-factor authentication.

Business ValuePrevent unauthorized account access.

Access Control

Role-based permissions ensure users only access what they need.

Business ValueEnforce least privilege principles.

Private File Storage

Operational documentation and attachments remain protected.

Business ValueSecure sensitive operational assets.

Auditability

Track important actions with activity history and audit capabilities.

Business ValueMaintain compliance and oversight.

Business Continuity

Operational knowledge remains available even during employee transitions.

Business ValueReduce operational disruption risk.

Our Security Principles

Protect Operational Knowledge

ExactlyHow is designed to preserve institutional knowledge while reducing unnecessary exposure to unauthorized internal or external parties.

Least Privilege

Users receive only the permissions necessary for their responsibilities, enforced through strict role-based access controls.

Transparency

We clearly communicate our implemented controls, planned security improvements, and current compliance status without exaggeration.

Continuous Improvement

Security is never finished. Our defensive posture, tooling, and policies evolve continuously as the platform grows.

Platform Security

Comprehensive controls built directly into the ExactlyHow application to ensure knowledge remains protected and accessible.

Authentication

Multi-Factor Authentication

Additional verification layer for user logins.

Benefit: Mitigates credential theft.

Session Management

Secure, time-bound authentication tokens.

Benefit: Reduces session hijacking risks.

Password Security

Strong hashing and complexity requirements.

Benefit: Protects against brute force attacks.

Role-Based Permissions

Creator / Editor

Can build and maintain operational knowledge.

Benefit: Restricts editing to authorized staff.

Viewer

Can search and read documented processes.

Benefit: Enables safe organization-wide access.

Administrator

Manages organization settings and users.

Benefit: Centralizes security governance.

Organization Isolation

Private Organization Data

Logical separation of customer workspaces.

Benefit: Prevents cross-tenant data leakage.

Secure Storage

Isolated operational knowledge repositories.

Benefit: Maintains data confidentiality.

Monitoring

Application Monitoring

Continuous oversight of platform health.

Benefit: Ensures high availability.

Error Monitoring

Real-time alerting for application exceptions.

Benefit: Accelerates incident response.

Audit History

Immutable logs of administrative actions.

Benefit: Supports compliance reviews.

Data Protection Architecture

Customer operational knowledge is protected through layered security controls rather than relying on a single defensive measure.

Users
ExactlyHow Web Application
Authentication
Application Layer
Encrypted Database
Encrypted File Storage
Automated Backups
Monitoring

Privacy Commitments

Customer Data Ownership

Customers retain full ownership and rights to their organizational data. ExactlyHow does not claim ownership of your operational knowledge.

Data Isolation

Each organization's information remains logically separated at the application level to prevent unauthorized access between tenants.

Privacy Commitment

ExactlyHow is committed to handling customer information responsibly and transparently, adhering to modern privacy principles.

Data Requests

Our support team assists enterprise customers with administrative data exports, deletion requests, and account-related privacy inquiries.

Compliance Roadmap

ExactlyHow accurately communicates current certifications and readiness. Compliance claims are updated only after requirements have been satisfied.

Implemented
  • Modern encryption
  • Role-Based Permissions
  • Secure Authentication
  • Audit History
  • Application Monitoring
  • Business Continuity Features
In Progress
  • Security Policies
  • Incident Response Procedures
  • Internal Security Program
Planned
  • SOC 2 Type II
  • ISO 27001
Supported
  • GDPR Readiness
  • HIPAA Readiness (for eligible deployments)
  • Enterprise Security Reviews
  • Vendor Questionnaires

Subprocessors

ExactlyHow carefully evaluates service providers that support delivery of the platform.

Supabase
Purpose: Database & Authentication
Location: United States
Website: supabase.com
Cloudflare
Purpose: Application Hosting, CDN & Security
Location: Global (Edge)
Website: cloudflare.com
GitHub
Purpose: Source Code Management
Location: United States
Website: github.com
Resend
Purpose: Transactional Email
Location: United States
Website: resend.com

Security Documentation

Security Overview

Available upon request.

Architecture Overview

Available upon request.

Incident Response Summary

Available upon request.

Vendor Security Questionnaire

Available upon request.

Penetration Testing Summary

Available when completed.

Compliance Documentation

Shared as certifications become available.

Help Us Improve Security

If you believe you have identified a potential security vulnerability, please contact our security team responsibly so we can investigate and resolve the issue.

Security FAQ

How is customer data protected?
Customer data is protected using modern encryption standards at rest (AES-256) and in transit (TLS 1.2+). We employ logical separation to ensure organizational data remains isolated.
Who owns the uploaded documentation?
You do. Customers retain complete ownership of all operational knowledge, files, and data uploaded to the ExactlyHow platform.
Is customer data encrypted?
Yes. All operational knowledge, user data, and file attachments are encrypted both in transit over public networks and at rest in our databases.
Can organizations control user permissions?
Yes, ExactlyHow features robust Role-Based Access Control (RBAC). Administrators can assign Viewer, Creator/Editor, and Admin roles to enforce least privilege.
Do you support Single Sign-On?
SSO and SCIM are not available yet — we're focused on Free and Business first. Business includes MFA, session controls, RBAC, and audit logs today.
How are backups managed?
We perform automated, continuous backups of our primary databases. Backups are encrypted and stored redundantly across multiple geographic zones.
Can security documentation be requested?
Yes. Prospects can request our Security Overview and Architecture Overview. Visit the Trust Center or contact us for vendor questionnaires.
Do you complete vendor security questionnaires?
Yes — reach out and our team can assist with standard vendor security questionnaires during procurement.
What certifications are currently available?
ExactlyHow is currently implementing its formal compliance program. SOC 2 Type II and ISO 27001 are planned on our compliance roadmap.
How is operational knowledge protected?
Beyond technical controls, ExactlyHow protects knowledge by ensuring it survives employee transitions. Our platform is a business continuity tool that secures institutional memory.

Ready to preserve your organization's operational knowledge?

Start documenting, organizing, searching and transferring operational knowledge with confidence.