Your code stays yours

We built Kira with the same security rigor we help you achieve. You control access, we respect boundaries.

You Control Privileges

Grant read-only access to specific repositories. Revoke anytime. We request only the minimum permissions needed for analysis.

Temporary Code Processing

Working copies of source code are processed in isolated temporary environments and scheduled for deletion after the relevant scan or troubleshooting process completes. Reports may retain the excerpts and evidence needed to explain findings.

Secure by Design

Security baked in from day one, not bolted on. Regular internal security reviews. Architected by engineers who've secured enterprise systems.

How we handle your data

1

Repository Access

You authorise access to selected repositories through supported GitHub account or App permissions. Permission scope depends on the integration and enabled features, such as pull-request comments.

2

Isolated Analysis

Code is cloned into a temporary processing environment with access controls designed to isolate customer workloads. Working copies are scheduled for cleanup after processing.

3

Results and Evidence

We retain analysis results such as findings, data-flow graphs, exploit evidence, and limited code excerpts needed to explain results. Retention and deletion are described in our Privacy Policy.

4

Instant Revocation

You can revoke the GitHub integration from your provider settings. Revocation prevents future provider access after the provider processes it and existing tokens expire or are invalidated.

Built by security engineers

Our team has secured infrastructure at Microsoft, Atlassian, and other enterprise environments. We know what "secure by design" actually means.

Encrypted

In transit and where appropriate at rest

Controlled

Least-privilege service access

Temporary

Working-copy retention

Trust at a glance

Clear status, direct answers, and the documents your legal and security teams need.

Compliance status

SOC 2 Type II

Readiness in progress

We are implementing and documenting internal controls in preparation for a future independent audit. Offgrid Security is not currently SOC 2 certified.

Available on request

Data Processing Agreement

Request our DPA for controller–processor terms, security obligations, data handling, deletion, and applicable international-transfer provisions.

Request the DPA →

Available on request

Security Whitepaper

Review Kira's architecture, access controls, data lifecycle, workload isolation, incident response, and enterprise deployment options.

Request the whitepaper →

Available on request

Subprocessor Information

Receive current information about relevant service providers, their processing purposes, and applicable processing locations.

Request subprocessor information →

Trust status last updated September 2026.

Deployment and data control

Enterprise deployments can be scoped around your infrastructure, key-management, residency, and contractual requirements.

On-prem deployment

Deploy Kira within your environment for regulated workloads and tighter infrastructure boundaries.

Bring your own keys

Use BYOK options to align model access and key management with your organisation's security controls.

Contractual commitments

Document agreed processing, retention, residency, and security requirements in your order form or DPA.

Questions about security?

We're happy to walk through our security architecture and answer any questions about how we handle your data.