We built Kira with the same security rigor we help you achieve. You control access, we respect boundaries.
Grant read-only access to specific repositories. Revoke anytime. We request only the minimum permissions needed for analysis.
Working copies of source code are processed in isolated temporary environments and scheduled for deletion after the relevant scan or troubleshooting process completes. Reports may retain the excerpts and evidence needed to explain findings.
Security baked in from day one, not bolted on. Regular internal security reviews. Architected by engineers who've secured enterprise systems.
You authorise access to selected repositories through supported GitHub account or App permissions. Permission scope depends on the integration and enabled features, such as pull-request comments.
Code is cloned into a temporary processing environment with access controls designed to isolate customer workloads. Working copies are scheduled for cleanup after processing.
We retain analysis results such as findings, data-flow graphs, exploit evidence, and limited code excerpts needed to explain results. Retention and deletion are described in our Privacy Policy.
You can revoke the GitHub integration from your provider settings. Revocation prevents future provider access after the provider processes it and existing tokens expire or are invalidated.
Our team has secured infrastructure at Microsoft, Atlassian, and other enterprise environments. We know what "secure by design" actually means.
In transit and where appropriate at rest
Least-privilege service access
Working-copy retention
We're happy to walk through our security architecture and answer any questions about how we handle your data.