Data Residency & Security at Koalr
Where your data lives, how it's protected, and what we never access.
What we store and where
| Data Category | What we store | Region | Retention |
|---|---|---|---|
| GitHub PR metadata | Titles, numbers, authors, timestamps, file names (NOT code content) | US (Oracle Cloud PostgreSQL) | 2 years |
| Jira issue metadata | Issue keys, titles, assignees, status, cycle times (NOT descriptions) | US | 2 years |
| Deployment events | Deploy timestamps, service names, outcomes (NOT deployment scripts) | US | 2 years |
| Risk model inputs | Computed signal values (NOT source code) | US | 1 year |
| AI chat messages | Your chat queries + AI responses (context includes metric summaries, NOT code) | US | 90 days |
| Authentication | Managed by Koalr's auth system — Ed25519-signed JWTs with session management | US | Koalr retention policy |
What we NEVER access
Source code content
We analyze file paths and change entropy, not file contents.
Credentials, secrets, or API keys in repositories
We never read file contents, only file paths and diff statistics.
Jira ticket descriptions or comment content
We sync issue keys, titles, assignees, and status transitions only.
PagerDuty runbook content
We use incident timestamps and service associations — not runbook text.
Infrastructure providers
Oracle Cloud
NestJS API, PostgreSQL, Redis — Oracle Always Free VM, US-based infrastructure
Oracle Cloud + Cloudflare
Next.js apps served via PM2 + Caddy on Oracle VM, global CDN via Cloudflare
Custom JWT
JWT issuance, multi-tenant orgs, SAML SSO — custom session management
PostgreSQL on Oracle Cloud
AES-256 encryption at rest, automated daily backups, point-in-time recovery
Oracle Cloud (self-managed)
API response cache only — no PII persisted in Redis
EU Data Residency
Currently US-only hosting. EU regional deployment is planned for 2026 Q3. Enterprise customers requiring EU residency today: contact us — we can expedite.
SOC 2 Type II
SOC 2 Type II audit initiated. Report expected Q3 2026. We will share the report under NDA with any customer in procurement review.
GDPR
Standard DPA available upon request. Koalr acts as data processor; your organization is the data controller. See our DPA page for the full agreement.
Questions about your specific compliance requirements?
Security reviews, custom DPAs, and pen test reports available under NDA.
Email [email protected]