Your data, your rules.
Strong sign‑in by default.
Second factor
Sign in with a password plus a passkey, an authenticator app, or a one-time recovery code. Administrators must use a second factor.
Passkeys
Passkeys use your device to confirm it is you, and cannot be phished or reused on another site.
Protected sign-up
New organizations pass a browser check and verify their email before they are activated.
Lockout and throttling
Repeated failed sign-ins are slowed and locked, and errors never say which credential was wrong.
Use the identity provider you already have.
OIDC and SAML 2.0
Sign in through your organization’s identity provider, optionally requiring Gnok’s second factor as well.
Enforced SSO
Require single sign-on for everyone, with passkey-protected emergency access for named administrators.
SCIM provisioning
Create, update and remove members from your identity provider, and map groups to application roles.
Least privilege, down to the row.
Roles and grants
Grant privileges on catalogs, schemas and tables to roles, and roles to people and service accounts.
Row policies and masking
Filter rows and mask columns by role, so one table can serve many audiences safely.
Application access
Each person needs an entitlement to use Gnok Studio, separate from their data permissions.
Audit
Sign-ins, grants and administrative changes are recorded for your organization’s review.
Encrypted in transit and at rest.
In transit
TLS on every public endpoint. Inside the platform, the query engine and the catalog authenticate each other with mutual TLS.
At rest
Table data, metadata and backups are stored encrypted.
Isolation
Each organization’s data, identities and settings are scoped to that organization. Background work runs under an identity of your organization, never a shared superuser.
Protected web front door
Gnok Studio and sign-in sit behind a web application firewall, with a browser check on sign-up and password reset.
AI that is off until you turn it on.
Opt-in per organization
No AI feature runs until the organization has a token budget and an administrator enables a rollout policy. On the free plan, Gnok grants the budget.
Policy you approve
Choose the provider and model, the operations allowed, and approve data egress and retention.
Budgets
Monthly token budgets cap spend, and every call is metered against them.
Report a security issue
If you believe you have found a vulnerability, email security@gnok.com with the details. Please don’t include another customer’s data, and give us a chance to fix it before you share it. Our disclosure policy explains what’s in scope and our safe harbor for good-faith research.