Privacy Policy
Last Updated: June 25, 2026
Krait Labs respects your privacy and is committed to transparency about how we collect, use, and protect your personal information.
Introduction
Krait Labs, Inc. (“Krait,” “we,” “us,” or “our”) respects your privacy and is committed to transparency regarding how we collect, use, and protect your personal information. This Privacy Policy describes our practices when you interact with our website (krait.io) and use our application services (collectively, the “Service”).
We are a Delaware C Corporation registered in the United States. Our principal place of business is located at:
This Privacy Policy applies to all visitors and users of our Service. By accessing or using Krait, you agree to the practices described in this policy. If you do not agree with any part of this policy, please do not use our Service.
What Personal Information We Collect
We collect personal information in several ways:
Information You Provide Directly
When you create an account, we collect:
- Email address
- Name or display name
- Username
- Organization or company name (optional)
- Workspace association (if applicable)
- Two-factor authentication (2FA) metadata
When you integrate third-party authentication (Google, GitHub, GitLab), we receive basic profile information from those providers, including email, name, username, avatar, and provider-specific user ID, subject to the permissions you grant.
Information We Collect Automatically
When you access our website or application, we automatically collect:
- IP address
- Browser type and version
- Device type and operating system
- Referring URL
- Pages or application routes visited
- Time spent on pages
- Authentication and login activity
- Session data
- Basic usage logs required for security and service operation
This information is collected through application logs, server logs, authentication systems, and infrastructure services.
Information from Integrations
When you connect your GitHub or GitLab repositories to Krait, we collect and process:
- Repository name, URL, and metadata
- Branch names and default branch information
- Commit metadata and history
- File paths and source code contents
- Configuration files and dependency manifests
- Infrastructure-as-code files
- CI/CD workflow files
- Package metadata and scan-related information
We use read-only access to analyze code for security issues, vulnerabilities, secrets, dependencies, and compliance findings. We do not modify repository contents unless you explicitly grant write permissions.
Container Image Scanning
When you scan Docker container images, we collect:
- Image name, tag, and digest
- Registry and repository references
- Base image information
- Operating system and package metadata
- Installed packages and versions
- Dockerfile or build configuration (if available)
- Layer metadata
- Vulnerability findings and CVE identifiers
- Remediation guidance and timestamps
AI Deep Scan Data
For AI Deep Scan and AI-assisted features, we process:
- Source code snippets and patterns
- File paths and configuration files
- Dependency information
- Infrastructure-as-code files
- CI/CD workflow files
- Application logic patterns
- Vulnerability context and suggested remediation
- AI-generated explanations and code suggestions
AI Deep Scan outputs are not guaranteed to be exhaustive or error-free and require your review.
Payment Information
We do not directly collect or store full payment card details. Payment processing is handled by Stripe. We may store billing metadata such as customer ID, subscription status, plan information, invoice references, billing email, and payment status.
API and Integration Logs
We log technical metadata from API calls and integrations for security, debugging, auditing, and abuse prevention:
- Timestamps and request IDs
- User and workspace identifiers
- Integration provider and endpoint
- HTTP method and response status
- IP address and user agent
- Rate-limit information
- Integration execution status
Cookies and Tracking
We use cookies necessary for authentication, session management, security, and application functionality. We use Keycloak for authentication and may use cookies for login sessions, identity provider flows, CSRF protection, 2FA, and user session state. These are primarily necessary or functional cookies. We do not use advertising cookies.
How We Use Your Information
We use the personal information we collect to:
- Operate and provide the Service
- Create and manage your account
- Authenticate and secure your account
- Process subscriptions and payments
- Provide customer support
- Detect and prevent abuse and security threats
- Troubleshoot technical issues and improve reliability
- Send service updates and security notices
- Conduct security monitoring and auditing
- Comply with legal obligations
- Improve our platform, features, and scanning accuracy
Anonymized Data Use
We may use anonymized and aggregated data for:
- Product improvement and analytics
- Service reliability and security enhancement
- Pattern analysis and research
- Industry benchmarking
This data cannot reasonably identify any customer, user, repository, organization, or confidential system.
Data Storage and Retention
Storage Location
Your data is stored primarily in us-east-1 (US East, N. Virginia). EU data storage options are planned and will be available to select during account setup in the future.
Your data is encrypted both in transit (TLS) and at rest (AES-256 encryption).
Data Retention
- Vulnerability findings and scan results: Retained until you disconnect the resource from Krait
- Raw code and container images: Temporary working copies may be created during scans but are deleted after scan completion
- Server logs (IP, browser, activity): Retained for 7 days
- User account data: Retained as long as your account is active
- Integration logs: Processed as needed for operation and security
Account Management
Your account remains active as long as you maintain your subscription or free tier registration. Account access can only be disabled by Krait for cause (violation of policies, non-payment, etc.).
Backups
We maintain backups of your data for service reliability. Deleted data may appear in backups for a limited period until backups are cycled.
Third-Party Services (Sub-processors)
We share your information with the following third-party services that are necessary to operate Krait:
| Service | Purpose | Data Shared |
|---|---|---|
| AWS | Cloud infrastructure, data storage | Repository metadata, scan results, logs |
| GitHub API | Repository access and scanning | Repository data, metadata |
| GitLab API | Repository access and scanning | Repository data, metadata |
| Slack | Notifications and integrations | Scan summaries, notification text |
| Linear | Ticket creation and management | Issue metadata, ticket references |
| Resend | Email delivery | User email addresses, notification content |
| Stripe | Payment processing | Billing information, customer ID |
We maintain Data Processing Agreements with our sub-processors to ensure they process data only as necessary and in compliance with this policy.
Data Security
We implement industry-standard security measures:
- TLS encryption for data in transit
- AES-256 encryption for data at rest
- Access controls and AWS IAM authentication
- Audit logging of all data access
- Regular security monitoring and threat detection
- Incident response procedures
- Secure credential and token management
However, no security system is completely impenetrable. While we implement reasonable safeguards, we cannot guarantee absolute security.
Your Data Rights
You have the following rights regarding your personal information:
Right of Access
You have the right to request and receive a copy of the personal information we hold about you.
Right of Correction
You can request that we correct inaccurate or incomplete information.
Right to Restrict Processing
You can request that we limit how we process your data.
Right of Data Portability
You can request a copy of your data in a portable format.
Right to Object
You can object to our processing of your data for marketing or other purposes.
Compliance
GDPR (EU Users)
If you are located in the European Union, European Economic Area, or Switzerland, our processing of your personal information is subject to the General Data Protection Regulation (GDPR). We process data based on:
- Your consent
- Contractual necessity to provide the Service
- Our legitimate business interests in operating and improving Krait
- Compliance with legal obligations
For EU data subjects, we comply with GDPR requirements including data subject rights, data security, and international transfer safeguards. We maintain a Data Processing Agreement available upon request.
CCPA (California Users)
We comply with applicable California Consumer Privacy Act (CCPA) requirements regarding personal information of California residents.
Retention Summary
We retain personal information for as long as necessary to provide the Service and comply with legal obligations. Specific retention periods are:
- Active accounts: Indefinitely until account deletion
- Deleted accounts: Purged within 30 days (backups may retain for up to 90 days)
- Server logs: 7 days
- Scan data: Until resource disconnection
- Billing records: As required by law (typically 7 years for US tax purposes)
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last Updated” date and posting the revised policy on our website. Material changes may require your explicit consent. Your continued use of Krait after changes indicates your acceptance of the updated policy.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Response Timeframe: We aim to respond to privacy inquiries within 30 days.
EU/EEA Residents
If you are located in the EU/EEA and have concerns about our processing of your data, you also have the right to lodge a complaint with your local data protection authority.
Children's Privacy
Krait is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take immediate action to delete it.
End of Privacy Policy