Security
What leaves your machines
One file: the graph. It is JSON and it contains route paths, the names of services, models, queues and hosts, the names of environment variables, dependency names and versions, file paths and line numbers that point at definitions and calls, commit counts and author names, and up to three lines of code around each item left for review, which the review inbox shows as evidence. It does not contain whole source files, the values of environment variables, credentials, or the content of your data.
Two ways to produce it:
- Hosted scanner. You add a read-only key to GitHub or Bitbucket. Our runner clones each repository shallowly, reads it, writes the graph and deletes the clone. The clone lives for the minutes a scan takes, on a disk that is wiped afterwards.
- Your own machines. The command-line tool runs in your CI or on a developer laptop and uploads only the graph with a workspace token. Only the graph reaches us. Available on every plan.
Keys
- One ed25519 key pair per workspace, generated on our servers with OpenSSH tooling. You see the public half; the private half is encrypted at rest with AES-256-GCM under a master key that lives in the server's environment, never in the database.
- The key is read-only because of where you add it: a GitHub deploy key without write access, a machine user with the Read role, or a Bitbucket access key, which can only clone and fetch. We document each path in the product.
- Rotate the key from the settings at any time; revoking it on the provider stops every future scan immediately.
- Workspace tokens for the command-line tool are shown once and stored hashed.
The runner
- Never executes your code. It parses files with tree-sitter and regular expressions and reads manifests and lock files. Dependency advisories come from registry metadata and the OSV database, by package name and version.
- Runs each scan in a fresh temporary directory, with a timeout and a size limit, and deletes it when done, on success or failure.
- Clones over SSH with the workspace key only, or over HTTPS for public repositories; outbound access is limited to code hosts and package registries.
Data at rest and in transit
- TLS 1.2 or higher on every connection, with certificates renewed automatically.
- Passwords hashed with bcrypt; sessions are signed tokens with a 30-day life.
- Graphs and their views are stored per organisation and workspace in object storage or encrypted disks, never shared between tenants; every read is scoped by the organisation of the signed-in member.
- Daily database backups kept 14 days, stored separately from the application host.
Access control
- Four roles: owner, admin, member, viewer. Only owners handle billing; only admins touch keys and workspaces; viewers read.
- Staff do not browse customer data. For support we may open a workspace read-only, for at most an hour, after you ask or agree; each session is written to an audit log you can see in the product. Customers on the Company plan can disable staff access entirely.
- Production access is limited to the people who operate the service, over SSH keys, with the host's own logging.
Retention and deletion
Imports beyond your plan's limit are deleted automatically, files included. Deleting a workspace removes its imports, declarations and key; deleting an organisation removes everything within 30 days, apart from billing records the law requires us to keep. You can export the graph at any time before.
Subprocessors
Hosting on Contabo (USA); Stripe for payments; Resend for email; TypeSafe AI for review suggestions (names, paths, hostnames and the three-line excerpts of review items); Sentry for error reports. The list, with what each one receives, is in the privacy policy and we notify customers 30 days before adding one.
Reporting a vulnerability
Write to security@kuuhaku.dev. We answer within two business days, keep you informed, and credit you if you want. Please do not access other customers' data while testing and give us a reasonable time to fix before publishing.
Incidents
If a security incident affects your data we notify the owners of the organisation by email within 72 hours of confirming it, with what happened, what was affected and what we did, and we notify the authorities where the law requires.