Koalr/Security/Data Residency
Enterprise compliance

Data Residency & Security at Koalr

Where your data lives, how it's protected, and what we never access.

What we store and where

Data CategoryWhat we storeRegionRetention
GitHub PR metadataTitles, numbers, authors, timestamps, file names (NOT code content)US (Railway PostgreSQL)2 years
Jira issue metadataIssue keys, titles, assignees, status, cycle times (NOT descriptions)US2 years
Deployment eventsDeploy timestamps, service names, outcomes (NOT deployment scripts)US2 years
Risk model inputsComputed signal values (NOT source code)US1 year
AI chat messagesYour chat queries + AI responses (context includes metric summaries, NOT code)US90 days
AuthenticationManaged entirely by Clerk — Koalr does not store passwords or session tokensUS (Clerk)Clerk retention policy

What we NEVER access

Source code content

We analyze file paths and change entropy, not file contents.

Credentials, secrets, or API keys in repositories

We never read file contents, only file paths and diff statistics.

Jira ticket descriptions or comment content

We sync issue keys, titles, assignees, and status transitions only.

PagerDuty runbook content

We use incident timestamps and service associations — not runbook text.

Infrastructure providers

Compute / API

Railway

SOC 2 Type II certified

NestJS API, PostgreSQL, Redis — US-based infrastructure

Frontend / CDN

Vercel

SOC 2 Type II certified

Next.js marketing site and app — global edge with US data origin

Auth

Clerk

SOC 2 Type II certified

JWT issuance, multi-tenant orgs, SAML SSO — Koalr never touches passwords

Database

PostgreSQL on Railway

Encrypted at rest, TLS in transit

AES-256 encryption at rest, automated daily backups, point-in-time recovery

Redis cache

Railway-managed

Ephemeral — 15-minute TTL

API response cache only — no PII persisted in Redis

🇪🇺

EU Data Residency

Currently US-only hosting. EU regional deployment on Railway is planned for 2026 Q3. Enterprise customers requiring EU residency today: contact us — we can expedite.

SOC 2 Type II

SOC 2 Type II audit initiated. Report expected Q3 2026. We will share the report under NDA with any customer in procurement review.

GDPR

Standard DPA available upon request. Koalr acts as data processor; your organization is the data controller. See our DPA page for the full agreement.

Questions about your specific compliance requirements?

Security reviews, custom DPAs, and pen test reports available under NDA.

Email security@koalr.com