Security Policy

Version

1.0

At KAIKI, security is at the core of everything we do. As a company building security tools for developers, we hold ourselves to the same standard we ask of you. This page outlines our practices and how we protect your data.

At a glance

  • Encryption in transit: all data is encrypted with TLS 1.3

  • No code storage: source code is processed in real time and never permanently stored

  • SOC2 ready: infrastructure and practices designed to meet SOC2 Type II standards

  • Secure authentication: GitHub OAuth 2.0 with minimal permission scopes. We never see your password

1. Data handling

Source code processing

When you start a scan, KAIKI fetches repository contents through the GitHub API, processes them in memory through our AI analysis pipeline, and returns the results. Your source code is never written to disk, and all code data is purged when the scan completes.

Scan results

We store your results securely against your account so you can open them in the dashboard. Those results cover detected secret types, file names, line numbers, severity levels, and remediation suggestions. They never contain the secret values themselves, only their location and type.

Authentication tokens

GitHub OAuth tokens are stored encrypted and are used only to access repositories on your behalf. Tokens are revoked immediately on account deletion.

2. Infrastructure security

  • Hosted on Vercel with enterprise-grade security, DDoS protection, and automatic SSL

  • AI inference through KAIKI Alpha over secure API communication

  • All API endpoints require authentication and are rate-limited

  • Regular dependency audits and vulnerability scanning of our own codebase

  • Environment variables and secrets managed through secure secret management

3. Access controls

Access to production systems is restricted to authorized personnel under the principle of least privilege. Team members only reach the systems and data their role requires, and all access is logged and audited.

4. Incident response

If a security incident occurs we investigate promptly, mitigate the impact, and notify affected users within 72 hours. Our response plan covers identification, containment, eradication, recovery, and lessons learned.

5. Responsible disclosure

We welcome security researchers who help us improve KAIKI. Report a vulnerability to barali@kaiki.dev with the subject line [SECURITY] Vulnerability Report. We acknowledge reports within 48 hours, provide regular updates, and ask for reasonable time to investigate before public disclosure.

6. Compliance

Our practices are designed to align with SOC2 Type II requirements and industry best practice, and our data handling complies with GDPR and CCPA. We are actively working toward formal certification as we scale.

7. Questions

For questions or concerns about our security practices, contact barali@kaiki.dev.

Ship With Confidence

Zero config, 50+ secret patterns, AI-powered analysis. Start scanning in seconds.