Security
Security and data
Where kanman runs, what it can touch, what model providers see and how long we keep things. Every claim links to the document behind it.
How data moves during a run
-
1. Your tracker and repo
GitHub, GitLab or Jira. kanman reads the story and checks out the code it needs.
-
2. Sandbox
A fresh, isolated environment per run. In Frankfurt, or on your self-hosted runner.
-
3. Model provider
Receives the prompts and code context the run needs. Your key, or usage through kanman.
-
4. Back to you
A pull request with the evidence pack, a tracker update and an audit entry.
The facts
-
Hosted in the EU
Coding sandboxes run in Frankfurt, Germany. Application data is stored in EU data centres.
Hosting and data residency (opens in a new tab) -
Self-hosted runner
Run the coding work inside your own network. Your code is checked out and executed there. Optionally model calls, reviews and every repository action too.
Run the self-hosted runner (opens in a new tab) -
Everything on your runners
Switch on "Run everything on our runners" and kanman's cloud never calls a model provider or your code host. Drafting, reviews, acceptance specs, pull requests and merges run on your runners with your own model account and tokens. kanman keeps the board, decisions, the audit log and the results your runners send back, never your code.
Run everything on your runners (opens in a new tab) -
A fresh sandbox for every run
Each run gets its own isolated environment, which is discarded afterwards. Nothing carries over between runs.
Sandbox and secrets (opens in a new tab) -
Secrets stay where they belong
Each team names the secrets its runs may use. Values exist only on the run's machine, are removed from logs and never land in the repository, the evidence pack or the audit log.
Sandbox and secrets (opens in a new tab) -
What model providers see
The prompts and code context a run needs. Bring your own keys for Anthropic, OpenAI, Azure OpenAI or AWS Bedrock and it runs under your contract.
What model providers see (opens in a new tab) -
Only what your policy allows
Repositories, paths, budgets and merge rights are set per team. By default a person merges.
Policies, presets and authority levels (opens in a new tab) -
Answers only from what you may see
When kanman answers from team knowledge (Confluence, Notion, repositories, documents), it checks what the asking person may see in the source and names its sources. Chat and team context are off until a team admin turns them on.
Team context and connectors (opens in a new tab) -
Single sign-on
Members sign in through your company's identity provider, with your password, MFA and session rules.
Account security and single sign-on (opens in a new tab) -
An audit log you can export
Every decision, approval and policy check is logged with who, what and when. Audit entries are kept for 365 days by default.
Retention and deletion (opens in a new tab) -
Deletion when you leave
When the contract ends you can export your data. We delete it within 30 days.
Data processing agreement -
DPA and subprocessors
A data processing agreement under GDPR Article 28, with the subprocessor list per executor.
DPA and subprocessors -
No training on your code
kanman does not use your code, stories or evidence to train models.
Privacy policy
Questions from your security team?
Send us your questionnaire. We answer it in writing.
Email your questions