Koalr/Security/Data Residency
Enterprise compliance

Data Residency & Security at Koalr

Where your data lives, how it's protected, and what we never access.

What we store and where

Data CategoryWhat we storeRegionRetention
GitHub PR metadataTitles, numbers, authors, timestamps, file names (NOT code content)US (Oracle Cloud PostgreSQL)2 years
Jira issue metadataIssue keys, titles, assignees, status, cycle times (NOT descriptions)US2 years
Deployment eventsDeploy timestamps, service names, outcomes (NOT deployment scripts)US2 years
Risk model inputsComputed signal values (NOT source code)US1 year
AI chat messagesYour chat queries + AI responses (context includes metric summaries, NOT code)US90 days
AuthenticationManaged by Koalr's auth system — Ed25519-signed JWTs with session managementUSKoalr retention policy

What we NEVER access

Source code content

We analyze file paths and change entropy, not file contents.

Credentials, secrets, or API keys in repositories

We never read file contents, only file paths and diff statistics.

Jira ticket descriptions or comment content

We sync issue keys, titles, assignees, and status transitions only.

PagerDuty runbook content

We use incident timestamps and service associations — not runbook text.

Infrastructure providers

Compute / API

Oracle Cloud

ISO 27001 certified

NestJS API, PostgreSQL, Redis — Oracle Always Free VM, US-based infrastructure

Frontend / CDN

Oracle Cloud + Cloudflare

ISO 27001 certified + CDN

Next.js apps served via PM2 + Caddy on Oracle VM, global CDN via Cloudflare

Auth

Custom JWT

Ed25519-signed tokens

JWT issuance, multi-tenant orgs, SAML SSO — custom session management

Database

PostgreSQL on Oracle Cloud

Encrypted at rest, TLS in transit

AES-256 encryption at rest, automated daily backups, point-in-time recovery

Redis cache

Oracle Cloud (self-managed)

Ephemeral — 15-minute TTL

API response cache only — no PII persisted in Redis

EU

EU Data Residency

Currently US-only hosting. EU regional deployment is planned for 2026 Q3. Enterprise customers requiring EU residency today: contact us — we can expedite.

SOC 2 Type II

SOC 2 Type II audit initiated. Report expected Q3 2026. We will share the report under NDA with any customer in procurement review.

GDPR

Standard DPA available upon request. Koalr acts as data processor; your organization is the data controller. See our DPA page for the full agreement.

Questions about your specific compliance requirements?

Security reviews, custom DPAs, and pen test reports available under NDA.

Email [email protected]