Security

Last updated 5 October 2026 · How the scanner touches your code, and what we keep

What leaves your machines

One file: the graph. It is JSON and it contains route paths, the names of services, models, queues and hosts, the names of environment variables, dependency names and versions, file paths and line numbers that point at definitions and calls, commit counts and author names, and up to three lines of code around each item left for review, which the review inbox shows as evidence. It does not contain whole source files, the values of environment variables, credentials, or the content of your data.

Two ways to produce it:

Keys

The runner

Data at rest and in transit

Access control

Retention and deletion

Imports beyond your plan's limit are deleted automatically, files included. Deleting a workspace removes its imports, declarations and key; deleting an organisation removes everything within 30 days, apart from billing records the law requires us to keep. You can export the graph at any time before.

Subprocessors

Hosting on Contabo (USA); Stripe for payments; Resend for email; TypeSafe AI for review suggestions (names, paths, hostnames and the three-line excerpts of review items); Sentry for error reports. The list, with what each one receives, is in the privacy policy and we notify customers 30 days before adding one.

Reporting a vulnerability

Write to security@kuuhaku.dev. We answer within two business days, keep you informed, and credit you if you want. Please do not access other customers' data while testing and give us a reasonable time to fix before publishing.

Incidents

If a security incident affects your data we notify the owners of the organisation by email within 72 hours of confirming it, with what happened, what was affected and what we did, and we notify the authorities where the law requires.