Security
You are handing us your source code. Here is the honest picture.
We are a young company with no certifications yet, and we would rather say that plainly than imply otherwise with a badge. What follows is what we access, what we keep, what we will not do, and what we have not built yet.
What we access
A read-only GitHub installation, scoped to the repositories you pick, on the branch you name. We never request write access, we do not open pull requests, and we do not push. Revoking the installation in GitHub cuts us off immediately.
What we store
The course we generated, the file paths and snippets it cites, and your team’s answers to recall checks. Data sits in an EU region, encrypted at rest and in transit. We do not keep a mirror of your repository lying around after generation.
Model providers
Generating a course means sending code to a language-model provider under a zero-retention agreement. Your code is not used to train anyone’s model, ours included. We will tell you which providers we use before you connect anything, and we will tell you if that list changes.
Deletion
Ask and we delete your repository data, courses, and answers. No retention clause designed to keep you around, and no export fee. Say the word and it is gone.
What we have not done yet
No SOC 2, no ISO 27001, no third-party penetration test. No SSO, no self-hosting, no audit log you can export. We will start the certification work when we have customers who need it, and we would rather you ask us where we are than assume.
- nextThird-party penetration test
- thenSSO and exportable audit log
- when neededSOC 2 Type II
Found something?
Write to crux@kiasm.dev. There is no separate security alias because there are three of us and one inbox — a person reads it, you get a reply within two working days, and we will not send a lawyer after anyone acting in good faith.