Scope and our privacy roles
This Privacy Policy applies to the KodeShield website, web application, APIs, SDKs, command-line tools, support interactions, and related services (collectively, the “Services”). It does not govern third-party products that you connect to KodeShield; those providers apply their own privacy terms.
KodeShield generally acts as a controller when handling website visitor data, account registration details, sales inquiries, and our own service analytics. When we process repository content, scan inputs, findings, or other data submitted by an organization through the platform, we generally act as a processor or service provider on that organization’s instructions. Your organization controls which repositories, users, integrations, and scan targets are connected.
Personal data we collect
The data we collect depends on how you interact with the Services.
Account and organization data
- Name, work email address, profile image, password credentials in protected form, and account preferences.
- Organization name, team membership, role, permissions, invitations, and workspace configuration.
- Identity information received from GitHub, Google, or an organization’s single sign-on provider when those login methods are used.
Development and security data
- Repository names, branches, commit and pull-request metadata, source-control identifiers, and installation details.
- Source code and configuration files accessed temporarily or submitted for authorized security scanning.
- Scan configuration and results, including vulnerabilities, dependency information, detected secrets, infrastructure findings, container findings, evidence, risk scores, and remediation status.
- Code excerpts, diffs, and technical context used to explain findings or generate remediation suggestions.
- DAST targets and, when configured by your organization, authentication material needed to test an authorized application.
Security scans can identify credentials or personal data that already exist in connected code or systems. Customers should connect only assets they are authorized to test and avoid submitting unnecessary personal or highly sensitive data.
Integration and support data
- Connection settings and authorization tokens for source-control, issue-tracking, messaging, CI/CD, and incident-response integrations selected by your organization.
- Communications, demo requests, feedback, troubleshooting material, and files you provide to support.
Usage, device, and log data
- IP address, browser and device information, pages visited, referring URLs, approximate location derived from IP, and timestamps.
- Authentication events, administrative actions, audit logs, API activity, performance measurements, errors, and security events.
- Interface preferences stored locally in your browser, such as theme, navigation state, favorites, and recently viewed pages.
How we use personal data
We use data to:
- Provide, operate, authenticate, and maintain the Services.
- Connect authorized repositories and integrations, run requested security scans, surface findings, and support remediation workflows.
- Manage organizations, memberships, roles, policies, notifications, reports, and customer preferences.
- Monitor availability, diagnose errors, prevent abuse, investigate security incidents, and enforce our agreements.
- Respond to support, demo, and sales requests and communicate service-related information.
- Understand feature usage and improve usability, reliability, performance, and security.
- Comply with applicable law, legal process, and regulatory obligations.
We do not use customer source code, detected secrets, or vulnerability findings to deliver third-party advertising.
Legal bases for processing
Where laws such as the European Union or United Kingdom data-protection rules require a legal basis, we rely on one or more of the following:
- Contract: processing needed to provide the Services requested by you or your organization.
- Legitimate interests: operating, securing, improving, and supporting a business-to-business security platform, balanced against your rights.
- Consent: where consent is requested, including for certain analytics or communications where required.
- Legal obligation: processing necessary to comply with applicable law or valid legal requests.
How we share personal data
We may disclose data to the following categories of recipients:
- Your organization: administrators and authorized members can access organization accounts, repositories, findings, audit information, and user activity according to their roles.
- Infrastructure and service providers: vendors that support hosting, storage, authentication, email delivery, observability, analytics, customer support, and security operations.
- Connected services: source-control, CI/CD, ticketing, messaging, incident-response, or identity providers when instructed by you or your organization.
- Professional advisers: auditors, insurers, legal advisers, and similar professionals subject to confidentiality obligations.
- Legal and safety recipients: authorities or other parties when reasonably necessary to comply with law, protect rights and safety, investigate fraud or abuse, or defend legal claims.
- Corporate transactions: parties involved in a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate protections.
We do not sell personal data for money. Some jurisdictions define “sale,” “sharing,” or “targeted advertising” broadly enough to cover certain analytics technologies. Where applicable, we provide and honor legally required choices.
AI-assisted features
KodeShield can use artificial-intelligence models to explain vulnerabilities, prioritize risk, and suggest code changes. Depending on your organization’s configuration, relevant finding details, code excerpts, or remediation context may be sent to an approved model provider or to a model environment selected by your organization.
AI-generated output can be incomplete or incorrect and should be reviewed before use. Organization administrators should configure only approved providers and avoid sending unnecessary personal data or secrets in prompts and remediation context. A connected AI provider’s processing may also be governed by that provider’s terms and your organization’s agreement with it.
Cookies, local storage, and analytics
We use browser technologies for the following purposes:
- Essential operation: session authentication, security, OAuth and SSO state, and other functionality needed to provide requested features.
- Preferences: local storage for interface settings such as theme, navigation state, saved views, favorites, and onboarding progress.
- Analytics and observability: Google Analytics helps us understand website interactions, while application observability tools help us measure performance and diagnose errors.
You can control cookies through your browser and, where available, our consent or privacy controls. Blocking essential storage may prevent parts of the Services from functioning. Browser-level preference signals are honored where required by applicable law and technically supported.
Data retention and deletion
We retain data only as long as reasonably necessary for the purposes described in this policy, to provide the Services, and to satisfy legal, security, accounting, and dispute resolution requirements.
- Account and organization data is generally retained while the account or customer relationship remains active and for a reasonable period afterward.
- Scan records and findings follow the retention window associated with the organization’s plan and configured policies. Authorized administrators may have additional retention or deletion controls.
- Temporary scan workspaces and credentials are intended to be limited to the time needed to perform authorized processing, subject to operational safeguards.
- Security logs, audit records, backups, and records required by law may remain for a limited period after other data is deleted.
Deletion from active systems may not immediately remove data from encrypted backups; backup copies are isolated and removed or overwritten according to the applicable backup lifecycle.
How we protect data
We use technical and organizational measures designed to protect data against unauthorized access, alteration, disclosure, or loss. These measures include access controls, tenant and role boundaries, authentication protections, audit logging, monitoring, secure development practices, and controls for integration credentials.
No system is completely secure. Customers are responsible for protecting their account credentials, limiting integrations and scan targets to authorized systems, configuring appropriate roles and retention settings, and promptly reporting suspected misuse.
International data transfers
KodeShield and its service providers may process data in countries other than the one where you live. Those countries may have different data-protection laws. Where required, we use recognized safeguards for restricted transfers, such as contractual protections, transfer assessments, or another lawful transfer mechanism.
Your privacy rights
Depending on your location and subject to legal exceptions, you may have rights to:
- Access or obtain a copy of personal data about you.
- Correct inaccurate or incomplete personal data.
- Request deletion or restriction of processing.
- Object to certain processing or withdraw consent where processing relies on consent.
- Receive certain data in a portable format.
- Opt out of certain sale, sharing, targeted advertising, or profiling activities where applicable.
- Appeal a denied request where local law provides that right.
- Complain to your local data-protection authority.
To submit a request, contact us using the details below. We may need to verify your identity and authority. If your account is managed by an employer or another customer, please contact that organization first; we may refer requests concerning customer- controlled data to the relevant organization. We will not discriminate against you for exercising applicable privacy rights.
Children’s privacy
The Services are intended for businesses and professional users and are not directed to children under 16. We do not knowingly collect personal data from children through the Services. If you believe a child has provided personal data to us, please contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy to reflect changes in our Services, practices, or legal obligations. We will post the revised policy on this page and update the “Last updated” date. If a change materially affects how we handle personal data, we will provide additional notice where required.
Contact us
For privacy questions, requests, or complaints, contact KodeShield at support@kodeshield.io. Please include “Privacy Request” in the subject line and identify your organization, if applicable, so we can route the request appropriately.
Questions about your data?
Contact our support team for privacy requests or questions about how your organization uses KodeShield.
Contact privacy support