Security

What changed: SOC 2 Type I status reads in preparation: controls are implemented and monitored continuously, with an audit firm not yet engaged.

Kosuke is a B2B AI coding platform. Customers connect their repositories and run agents against their real stack, so trust depends on how we handle their code, their data, and the environments we create for them. This page summarizes our security posture in plain language. The legally binding controls live in the Terms of Service and the Data Processing Agreement.

Where your code lives

  • Source code stays in your GitHub repositories. Kosuke does not become the system of record for your code.
  • Every change is delivered as a standard pull request in your own repository, so nothing depends on a proprietary runtime and nothing is stranded if you stop using Kosuke.
  • Sandbox and preview environments are isolated per change and torn down after use.

Encryption

  • In transit: TLS 1.2 or higher for all customer-facing endpoints, APIs, and internal service-to-service traffic.
  • At rest: AES-256 (or provider equivalent) for stored customer data, including attachments, project records, and credentials.

Access control

  • Role-based access with least-privilege defaults.
  • Multi-factor authentication required for all administrative access.
  • Audit logging of access to customer Personal Data.
  • Confidentiality obligations on all personnel and contractors.

AI processing

  • We do not train on customer code or on agent transcripts. Transcripts are not used for internal evaluation, benchmarking, or model tuning either.
  • Where Kosuke controls the provider relationship, we use business or API offerings and enable zero data retention where the provider makes it available.
  • Organizations that supply their own provider credentials control that relationship, including its retention and model-training settings.

Breach notification

  • Notification to affected customers without undue delay, and in any event within 72 hours of becoming aware, in accordance with GDPR Article 33 and Section 6.2 of the DPA.

Sub-processors

The current list of Sub-processors that may process customer Personal Data is published at /legal/subprocessors with 30 days advance notice of any change.

Data retention and deletion

On termination, or on deletion of an account or workspace, Personal Data is returned or securely destroyed within 30 days, per Section 7 of the DPA. Limited copies may remain in backups and security logs for a limited period. Your repositories are unaffected, because they were never ours.

Certifications

  • SOC 2 Type I: in preparation. Controls are implemented and monitored continuously, and an audit firm has not yet been engaged. This page is updated when the status changes.
  • GDPR: addressed contractually through the Data Processing Agreement, which incorporates the Standard Contractual Clauses, and through the published Sub-processor list.
  • ISO 27001: not currently in scope.
  • HIPAA: not claimed. Kosuke does not offer a Business Associate Agreement, and Section 2.3 of the DPA excludes special categories of personal data under GDPR Article 9, which includes health data, unless expressly authorized in writing.

Kosuke does not claim certifications it does not hold. If your procurement team requires a specific certification or vendor security questionnaire, contact security@kosuke.ai.

Reporting a vulnerability

If you believe you've found a security issue in Kosuke's own systems, email security@kosuke.ai. We acknowledge reports within 2 business days and credit researchers who disclose responsibly.

Contact

Security questions, DPA execution, vendor questionnaires, COI requests: security@kosuke.ai.