BlokNotesBeta
Security & data

Your workspace holds your business. We treat it that way.

BlokNotes stores client records, financial documents and credentials — so security is architecture, not an afterthought. Here is how it works, in plain language.

Workspace isolation

Every workspace is a strictly isolated tenant. All queries are scoped to the workspace at the data layer, so content never crosses workspace boundaries.

Role-based access

Owner, editor and reader roles control who can manage, change or merely see. Invitations expire, and access can be revoked at any time.

Encryption where it counts

Vault secrets are encrypted with AES-GCM using keys derived from your own password (PBKDF2-SHA256) — a password BlokNotes never stores. Workspace AI provider keys are stored encrypted as well.

Data regions

Choose an EU or US data region per workspace at creation, so your content is hosted where it suits you and your customers' compliance needs.

Sharing with limits

Public notes are explicit, read-only opt-ins. Secret shares carry expiry times, read-count limits, optional passwords, full audit trails and instant revocation.

Your data leaves with you

Workspace export is built in, and generated documents support English, Dutch, French and German. Deletion flows include soft-delete protection against accidents.

Trusted building blocks

BlokNotes builds on specialized providers rather than reinventing sensitive infrastructure:

Authentication
Clerk — dedicated identity provider with modern session security
Payments (when plans arrive)
Stripe — card data never touches BlokNotes servers
File storage
Cloud object storage with short-lived, pre-signed download links
AI providers
OpenAI, Anthropic, Google — request-scoped, no training on your content

AI and your content

AI features send only the content needed for your specific request to the model provider, under API terms that exclude training use. If you connect your own API key, requests run on your own provider account. AI-generated research findings stay marked as proposals until a human confirms them.

A note on the beta

BlokNotes is in public beta and does not yet hold formal certifications like SOC 2 or ISO 27001. What you read above is engineering reality, not a compliance badge — and if your situation requires specific guarantees, talk to us before relying on the product for it.

Start working in one connected workspace

BlokNotes is free during the public beta — every feature, no usage limits, no credit card.