Limited Availability
Security

Your data, your rules.

Each organization's identities, data and settings are its own. Here is how Gnok protects them.
Identity

Strong sign‑in by default.

Sign-in is one page: organization, email, password and a second factor. Your bookmark can fill in your organization.
Account access guide →
  • Second factor

    Sign in with a password plus a passkey, an authenticator app, or a one-time recovery code. Administrators must use a second factor.

  • Passkeys

    Passkeys use your device to confirm it is you, and cannot be phished or reused on another site.

  • Protected sign-up

    New organizations pass a browser check and verify their email before they are activated.

  • Lockout and throttling

    Repeated failed sign-ins are slowed and locked, and errors never say which credential was wrong.

Single sign-on

Use the identity provider you already have.

Connect Gnok to your identity provider so people join, change roles and leave in one place.
Authentication →
  • OIDC and SAML 2.0

    Sign in through your organization’s identity provider, optionally requiring Gnok’s second factor as well.

  • Enforced SSO

    Require single sign-on for everyone, with passkey-protected emergency access for named administrators.

  • SCIM provisioning

    Create, update and remove members from your identity provider, and map groups to application roles.

Access control

Least privilege, down to the row.

Sharing a worksheet never shares the data behind it: every query runs with the permissions of the person running it.
Roles and grants →
  • Roles and grants

    Grant privileges on catalogs, schemas and tables to roles, and roles to people and service accounts.

  • Row policies and masking

    Filter rows and mask columns by role, so one table can serve many audiences safely.

  • Application access

    Each person needs an entitlement to use Gnok Studio, separate from their data permissions.

  • Audit

    Sign-ins, grants and administrative changes are recorded for your organization’s review.

Data protection

Encrypted in transit and at rest.

Gnok runs the infrastructure; your organization controls who can see what.
  • In transit

    TLS on every public endpoint. Inside the platform, the query engine and the catalog authenticate each other with mutual TLS.

  • At rest

    Table data, metadata and backups are stored encrypted.

  • Isolation

    Each organization’s data, identities and settings are scoped to that organization. Background work runs under an identity of your organization, never a shared superuser.

  • Protected web front door

    Gnok Studio and sign-in sit behind a web application firewall, with a browser check on sign-up and password reset.

AI Governance

AI that is off until you turn it on.

AI functions send selected text to a language-model provider. Your organization decides whether and how that happens.
AI Governance →
  • Opt-in per organization

    No AI feature runs until the organization has a token budget and an administrator enables a rollout policy. On the free plan, Gnok grants the budget.

  • Policy you approve

    Choose the provider and model, the operations allowed, and approve data egress and retention.

  • Budgets

    Monthly token budgets cap spend, and every call is metered against them.

Report a security issue

If you believe you have found a vulnerability, email security@gnok.com with the details. Please don’t include another customer’s data, and give us a chance to fix it before you share it. Our disclosure policy explains what’s in scope and our safe harbor for good-faith research.