Server-only data
Browsers use Appwrite directly only for authentication. Product records and private files are accessed through KnowHow’s default-deny policy layer.
Security overview
KnowHow’s pilot architecture combines verified identities, administrator MFA, server-side authorization, private storage, short-lived extension credentials, and auditable exceptional access.
Browsers use Appwrite directly only for authentication. Product records and private files are accessed through KnowHow’s default-deny policy layer.
Organization administration does not confer guide access. Workspace membership and audiences determine who can view content.
Exceptional support access requires customer approval, a stated reason, a short expiry, reauthentication, notifications, and a complete audit trail.
Do not capture or upload credentials, secrets, payment information, health information, national IDs, or other sensitive or special-category data. Independent media disaster recovery and contractual recovery guarantees are not part of the pilot.