{
  "catalog": {
    "name": "Konyx Knowledge Catalog",
    "version": "1.0",
    "updatedAt": "2026-10-02",
    "owner": "Konyx Industrial Intelligence",
    "contact": "ceo@konyxai.com",
    "site": "https://konyxai.com",
    "description": "The structured, versioned facts about Konyx — industrial procurement software for MRO and indirect spend — that konyxai.com and AI assistants answer from. Every record names its source and the date it was last checked against the product; a capability says whether it is live, planned or not offered.",
    "formats": {
      "html": "https://konyxai.com/knowledge",
      "json": "https://konyxai.com/api/knowledge",
      "markdown": "https://konyxai.com/llms-full.txt",
      "index": "https://konyxai.com/llms.txt"
    }
  },
  "domain": {
    "slug": "control",
    "name": "Control, security and audit",
    "description": "How Konyx keeps a person in charge of every send, isolates each company, and records what happened.",
    "question": "How is Konyx controlled and secured?",
    "url": "https://konyxai.com/knowledge/control"
  },
  "records": [
    {
      "id": "control.person-presses-send",
      "domain": "control",
      "slug": "person-presses-send",
      "name": "A person presses Send",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — decision log, 15 Sep 2026"
      },
      "audiences": [
        "finance",
        "IT and security"
      ],
      "summary": "AI reads and drafts; it never sends. Every RFQ and every purchase order waits for a named person who holds the permission to open it, review the exact email, acknowledge the review and press Send.",
      "related": [
        "capabilities.rfq",
        "capabilities.autonomous-purchasing"
      ],
      "url": "https://konyxai.com/knowledge/control#person-presses-send"
    },
    {
      "id": "control.permissions-on-every-call",
      "domain": "control",
      "slug": "permissions-on-every-call",
      "name": "Permissions on every call",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — §3.1"
      },
      "audiences": [
        "IT and security"
      ],
      "summary": "Drafting an RFQ and sending it are separate permissions, checked in the API on every request — not in the screen. An employee who cannot send escalates by design, not by convention; calling the endpoint directly is refused.",
      "related": [
        "capabilities.roles-and-permissions",
        "use-cases.employee-cannot-send"
      ],
      "url": "https://konyxai.com/knowledge/control#permissions-on-every-call"
    },
    {
      "id": "control.append-only-audit",
      "domain": "control",
      "slug": "append-only-audit",
      "name": "An audit trail that cannot drift",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — §3.7"
      },
      "audiences": [
        "IT and security",
        "finance"
      ],
      "summary": "Every state change is written in the same transaction as the change itself, by the one function allowed to change a status, and the log is append-only at the database level. The trail cannot disagree with what happened because nothing else can write either.",
      "related": [
        "capabilities.activity-log",
        "faq.audit-trail"
      ],
      "url": "https://konyxai.com/knowledge/control#append-only-audit"
    },
    {
      "id": "control.discovered-vendors-reviewed",
      "domain": "control",
      "slug": "discovered-vendors-reviewed",
      "name": "Discovered vendors are reviewed",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — §3.4"
      },
      "audiences": [
        "buyers",
        "IT and security"
      ],
      "summary": "A vendor found on the web is never emailed until a person picks it and checks the address on the send screen. That one gate is the quality gate, the deliverability gate and the legal gate.",
      "related": [
        "capabilities.vendor-discovery"
      ],
      "url": "https://konyxai.com/knowledge/control#discovered-vendors-reviewed"
    },
    {
      "id": "control.tenant-isolation",
      "domain": "control",
      "slug": "tenant-isolation",
      "name": "Each company is isolated in the database",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — §3.1"
      },
      "audiences": [
        "IT and security"
      ],
      "summary": "Row-level security is forced on every tenant-scoped table and the application connects as a role that cannot bypass it. Two automated checks fail the build if a table lacks its policy or a query bypasses the scoped accessor, and a live test proves a cross-company read is refused. Konyx staff use the same permission wall, never a database console.",
      "related": [
        "faq.data-isolation",
        "control.architecture"
      ],
      "url": "https://konyxai.com/knowledge/control#tenant-isolation"
    },
    {
      "id": "control.terms-and-privacy",
      "domain": "control",
      "slug": "terms-and-privacy",
      "name": "Terms of Service and Privacy Policy",
      "verifiedAt": "2026-10-01",
      "version": 1,
      "source": {
        "kind": "website",
        "ref": "konyxai.com — /terms and /privacy"
      },
      "audiences": [
        "IT and security",
        "buyers"
      ],
      "summary": "The Terms of Service and Privacy Policy are published at konyxai.com/terms and konyxai.com/privacy. Everyone signing in to the company app ticks a box agreeing to both, and the version each person agreed to, and when, is recorded against them and in the activity log.",
      "body": [
        "The sign-in and activation forms refuse to go on without the box, and so does the API behind them. When the terms change, the next sign-in asks again.",
        "Konyx does not sell personal information or use it for advertising. Google Analytics runs on the site and the company app only when switched on, with advertising features off; it receives page paths with record numbers blanked, counts and choices, and the person and company as internal codes — never names, emails or what anyone typed. It never runs on the vendor quote link, or when the browser sends Global Privacy Control."
      ],
      "fields": {
        "Terms of Service": "https://konyxai.com/terms",
        "Privacy Policy": "https://konyxai.com/privacy",
        "Recorded per person": [
          "terms version agreed to",
          "when"
        ]
      },
      "related": [
        "control.tenant-isolation",
        "faq.hosting",
        "faq.ai-models"
      ],
      "url": "https://konyxai.com/knowledge/control#terms-and-privacy"
    },
    {
      "id": "control.no-default-accounts",
      "domain": "control",
      "slug": "no-default-accounts",
      "name": "No default accounts, anywhere",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — decision log, 15 Sep 2026"
      },
      "audiences": [
        "IT and security"
      ],
      "summary": "Companies and their owners are created only by Konyx staff from the console, which emails the owner a temporary password. Nothing can be signed into that a human did not deliberately create, and every credential has one auditable origin.",
      "related": [
        "control.architecture"
      ],
      "url": "https://konyxai.com/knowledge/control#no-default-accounts"
    },
    {
      "id": "control.architecture",
      "domain": "control",
      "slug": "architecture",
      "name": "The shape of the system",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — decision log, 16 Sep 2026"
      },
      "audiences": [
        "IT and security"
      ],
      "summary": "One backend owns the database, the sessions, the permissions, email and AI, and cannot be reached without a key the browser never holds. The web applications are database-free: the browser calls their own backend, which forwards to the API with that key and the person's session. Sessions live in an httpOnly cookie; the token never appears in a response body.",
      "body": [
        "Every route that can be abused is rate-limited in the database, so every instance sees the same count: sign-in, activation, RFQ sending, AI requests, web vendor search, the vendor quote link, imports and the rest. State changes are refused unless the request came from the application's own origin. Security headers are set on every response; secrets live in a managed secret store, not in code."
      ],
      "related": [
        "faq.hosting",
        "control.tenant-isolation"
      ],
      "url": "https://konyxai.com/knowledge/control#architecture"
    },
    {
      "id": "control.ai-provenance",
      "domain": "control",
      "slug": "ai-provenance",
      "name": "Every model call is recorded",
      "verifiedAt": "2026-09-26",
      "version": 1,
      "source": {
        "kind": "plan",
        "ref": "Engineering Action Plan — §3.8"
      },
      "audiences": [
        "IT and security",
        "finance"
      ],
      "summary": "Each call to a model is recorded with who made it, which task and prompt version, and what it cost, and is shown per company and platform-wide. Each extracted field keeps its state, its evidence and the call that produced it, so the answer to why did it say that is always on file.",
      "related": [
        "how-it-works.what-the-ai-does",
        "faq.ai-models"
      ],
      "url": "https://konyxai.com/knowledge/control#ai-provenance"
    }
  ]
}