Legal

Privacy Policy

Last Updated: June 25, 2026

Krait Labs respects your privacy and is committed to transparency about how we collect, use, and protect your personal information.

Introduction

Krait Labs, Inc. (“Krait,” “we,” “us,” or “our”) respects your privacy and is committed to transparency regarding how we collect, use, and protect your personal information. This Privacy Policy describes our practices when you interact with our website (krait.io) and use our application services (collectively, the “Service”).

We are a Delaware C Corporation registered in the United States. Our principal place of business is located at:

Krait Labs, Inc.405 Serrano Drive, 9FSan Francisco, CA 94132USA

This Privacy Policy applies to all visitors and users of our Service. By accessing or using Krait, you agree to the practices described in this policy. If you do not agree with any part of this policy, please do not use our Service.

What Personal Information We Collect

We collect personal information in several ways:

Information You Provide Directly

When you create an account, we collect:

  • Email address
  • Name or display name
  • Username
  • Organization or company name (optional)
  • Workspace association (if applicable)
  • Two-factor authentication (2FA) metadata

When you integrate third-party authentication (Google, GitHub, GitLab), we receive basic profile information from those providers, including email, name, username, avatar, and provider-specific user ID, subject to the permissions you grant.

Information We Collect Automatically

When you access our website or application, we automatically collect:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Referring URL
  • Pages or application routes visited
  • Time spent on pages
  • Authentication and login activity
  • Session data
  • Basic usage logs required for security and service operation

This information is collected through application logs, server logs, authentication systems, and infrastructure services.

Information from Integrations

When you connect your GitHub or GitLab repositories to Krait, we collect and process:

  • Repository name, URL, and metadata
  • Branch names and default branch information
  • Commit metadata and history
  • File paths and source code contents
  • Configuration files and dependency manifests
  • Infrastructure-as-code files
  • CI/CD workflow files
  • Package metadata and scan-related information

We use read-only access to analyze code for security issues, vulnerabilities, secrets, dependencies, and compliance findings. We do not modify repository contents unless you explicitly grant write permissions.

Container Image Scanning

When you scan Docker container images, we collect:

  • Image name, tag, and digest
  • Registry and repository references
  • Base image information
  • Operating system and package metadata
  • Installed packages and versions
  • Dockerfile or build configuration (if available)
  • Layer metadata
  • Vulnerability findings and CVE identifiers
  • Remediation guidance and timestamps

AI Deep Scan Data

For AI Deep Scan and AI-assisted features, we process:

  • Source code snippets and patterns
  • File paths and configuration files
  • Dependency information
  • Infrastructure-as-code files
  • CI/CD workflow files
  • Application logic patterns
  • Vulnerability context and suggested remediation
  • AI-generated explanations and code suggestions

AI Deep Scan outputs are not guaranteed to be exhaustive or error-free and require your review.

Payment Information

We do not directly collect or store full payment card details. Payment processing is handled by Stripe. We may store billing metadata such as customer ID, subscription status, plan information, invoice references, billing email, and payment status.

API and Integration Logs

We log technical metadata from API calls and integrations for security, debugging, auditing, and abuse prevention:

  • Timestamps and request IDs
  • User and workspace identifiers
  • Integration provider and endpoint
  • HTTP method and response status
  • IP address and user agent
  • Rate-limit information
  • Integration execution status

Cookies and Tracking

We use cookies necessary for authentication, session management, security, and application functionality. We use Keycloak for authentication and may use cookies for login sessions, identity provider flows, CSRF protection, 2FA, and user session state. These are primarily necessary or functional cookies. We do not use advertising cookies.

How We Use Your Information

We use the personal information we collect to:

  • Operate and provide the Service
  • Create and manage your account
  • Authenticate and secure your account
  • Process subscriptions and payments
  • Provide customer support
  • Detect and prevent abuse and security threats
  • Troubleshoot technical issues and improve reliability
  • Send service updates and security notices
  • Conduct security monitoring and auditing
  • Comply with legal obligations
  • Improve our platform, features, and scanning accuracy

Anonymized Data Use

We may use anonymized and aggregated data for:

  • Product improvement and analytics
  • Service reliability and security enhancement
  • Pattern analysis and research
  • Industry benchmarking

This data cannot reasonably identify any customer, user, repository, organization, or confidential system.

Data Storage and Retention

Storage Location

Your data is stored primarily in us-east-1 (US East, N. Virginia). EU data storage options are planned and will be available to select during account setup in the future.

Your data is encrypted both in transit (TLS) and at rest (AES-256 encryption).

Data Retention

  • Vulnerability findings and scan results: Retained until you disconnect the resource from Krait
  • Raw code and container images: Temporary working copies may be created during scans but are deleted after scan completion
  • Server logs (IP, browser, activity): Retained for 7 days
  • User account data: Retained as long as your account is active
  • Integration logs: Processed as needed for operation and security

Account Management

Your account remains active as long as you maintain your subscription or free tier registration. Account access can only be disabled by Krait for cause (violation of policies, non-payment, etc.).

Backups

We maintain backups of your data for service reliability. Deleted data may appear in backups for a limited period until backups are cycled.

Third-Party Services (Sub-processors)

We share your information with the following third-party services that are necessary to operate Krait:

ServicePurposeData Shared
AWSCloud infrastructure, data storageRepository metadata, scan results, logs
GitHub APIRepository access and scanningRepository data, metadata
GitLab APIRepository access and scanningRepository data, metadata
SlackNotifications and integrationsScan summaries, notification text
LinearTicket creation and managementIssue metadata, ticket references
ResendEmail deliveryUser email addresses, notification content
StripePayment processingBilling information, customer ID

We maintain Data Processing Agreements with our sub-processors to ensure they process data only as necessary and in compliance with this policy.

Data Security

We implement industry-standard security measures:

  • TLS encryption for data in transit
  • AES-256 encryption for data at rest
  • Access controls and AWS IAM authentication
  • Audit logging of all data access
  • Regular security monitoring and threat detection
  • Incident response procedures
  • Secure credential and token management

However, no security system is completely impenetrable. While we implement reasonable safeguards, we cannot guarantee absolute security.

Your Data Rights

You have the following rights regarding your personal information:

Right of Access

You have the right to request and receive a copy of the personal information we hold about you.

Right of Correction

You can request that we correct inaccurate or incomplete information.

Right to Restrict Processing

You can request that we limit how we process your data.

Right of Data Portability

You can request a copy of your data in a portable format.

Right to Object

You can object to our processing of your data for marketing or other purposes.

To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within 30 days.

Compliance

GDPR (EU Users)

If you are located in the European Union, European Economic Area, or Switzerland, our processing of your personal information is subject to the General Data Protection Regulation (GDPR). We process data based on:

  • Your consent
  • Contractual necessity to provide the Service
  • Our legitimate business interests in operating and improving Krait
  • Compliance with legal obligations

For EU data subjects, we comply with GDPR requirements including data subject rights, data security, and international transfer safeguards. We maintain a Data Processing Agreement available upon request.

CCPA (California Users)

We comply with applicable California Consumer Privacy Act (CCPA) requirements regarding personal information of California residents.

Retention Summary

We retain personal information for as long as necessary to provide the Service and comply with legal obligations. Specific retention periods are:

  • Active accounts: Indefinitely until account deletion
  • Deleted accounts: Purged within 30 days (backups may retain for up to 90 days)
  • Server logs: 7 days
  • Scan data: Until resource disconnection
  • Billing records: As required by law (typically 7 years for US tax purposes)

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last Updated” date and posting the revised policy on our website. Material changes may require your explicit consent. Your continued use of Krait after changes indicates your acceptance of the updated policy.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Email: [email protected]

Krait Labs, Inc.405 Serrano Drive, 9FSan Francisco, CA 94132USA

Response Timeframe: We aim to respond to privacy inquiries within 30 days.

EU/EEA Residents

If you are located in the EU/EEA and have concerns about our processing of your data, you also have the right to lodge a complaint with your local data protection authority.

Children's Privacy

Krait is not intended for users under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected information from a minor, we will take immediate action to delete it.

End of Privacy Policy