Privacy and Security

From Knowledge Commons
Jump to navigation Jump to search

Every aspect of the project will follow generally accepted best practices for security.

Architectural Goals

  • Each user owns their own data and everything is private by default
  • Within a few years, we plan to have independent audits to validate:
    • Technical: application, source code, infrastructure, multi-tenant isolation
    • Resiliency: data privacy, backup and disaster recovery
    • Procedural: SOC 2, ISO 27001
  • Infrastructure should be able to scale to 100,000 users
  • Use open source technologies whenever possible
  • Cost optimization
  • Automate as much as possible to minimize time required for operational maintenance

Software License Model

  • If we make our code available open source, we cannot restrict platform usage to non-commercial