Skip to content

Security

Security and data

Where kanman runs, what it can touch, what model providers see and how long we keep things. Every claim links to the document behind it.

How data moves during a run

  1. 1. Your tracker and repo

    GitHub, GitLab or Jira. kanman reads the story and checks out the code it needs.

  2. 2. Sandbox

    A fresh, isolated environment per run. In Frankfurt, or on your self-hosted runner.

  3. 3. Model provider

    Receives the prompts and code context the run needs. Your key, or usage through kanman.

  4. 4. Back to you

    A pull request with the evidence pack, a tracker update and an audit entry.

The facts

Questions from your security team?

Send us your questionnaire. We answer it in writing.

Email your questions