Kodus Trust Center

Transparency about security, compliance, and infrastructure in one place.

Kodus logo

Trust Center

Kodus

AI code review with control and minimal noise

Kody is an open source AI code review agent with deep knowledge of your business rules and architecture, aligned with your policies and compliance requirements.

Certifications & compliance

SOC 2

Scope: Security and Availability

In Progress

ISO 27001

Scope: Information Security Management for global operations

In Progress

LGPD

Scope: Data processor commitments and internal policies

Compliant

GDPR

Scope: Data processor commitments and international transfer safeguards

Compliant
Policies & controls

Access Management

Owner: Security and Compliance • SSO and MFA enforced for corporate accounts with least privilege access reviews every quarter.

Cadence: Reviewed annually or after major changes

Incident Management

Owner: Security and Compliance • Defined severity levels, logging and 72 hour client notification for incidents involving personal data.

Cadence: Reviewed annually and after major incidents

Backup and Disaster Recovery

Owner: Infrastructure and Security • Daily encrypted backups on AWS and DigitalOcean with defined RPO and RTO.

Cadence: Backup restore tests performed periodically and policy reviewed annually

Secure SDLC

Owner: Engineering and Security • Secure coding standards, automated tests and mandatory AI code review before merge.

Cadence: Reviewed annually and aligned with engineering practices

Available documents

Security and Data Usage Overview

Overview

High level overview of Kodus security architecture, controls and data usage.

PublicSecurityArchitecture

Privacy Policy

Privacy

Details on what personal data we collect, how we use it and the rights of data subjects.

PublicGDPRLGPD

Data Processing Agreement (DPA)

Data Protection

Standard data processing terms for customers where Kodus acts as data processor.

PublicDPASCC

Data Protection and Data Retention Policy

Policy

Internal rules for data minimization, retention periods and secure disposal.

Request onlyRetentionCompliance

Information Security Policy

Policy

Company wide information security principles, access control and infrastructure requirements.

Request onlySecurityGovernance

Incident Response and Breach Notification Policy

Policy

Procedures for detecting, investigating and notifying incidents, including 72 hour breach notifications.

Request onlyIncidentsBreach Notification

Disaster Recovery and Backup Policy

Policy

Backup strategy, RPO and RTO objectives, and disaster recovery procedures.

Request onlyDRBackup

SDLC Policy

Policy

Secure software development life cycle, including mandatory AI powered code review with Kody.

Request onlySDLCDevelopment
Subprocessors (12)
AW

Amazon Web Services (AWS)

United StatesCloud infrastructure and storage

Primary hosting environment for application servers, databases and backups.

GC

Google Cloud Platform (GCP)

United StatesCloud infrastructure and analytics

Used for certain data processing jobs and analytics workloads.

D

DigitalOcean

United StatesCloud infrastructure

Used for auxiliary services and background workers.

L

LangSmith

United StatesLLM observability and evaluation

Helps monitor and evaluate AI prompts and model outputs.

S

Sentry

United StatesError monitoring and performance

Captures application errors and performance data.

C

Composio

United StatesIntegrations and automation

Connects Kody with external tools and APIs.

S

Stripe

United StatesPayments and billing

Processes subscription payments and invoices.

A

Anthropic

United StatesAI model provider

Provides managed LLMs for AI code review features.

O

OpenAI

United StatesAI model provider

Provides managed LLMs for AI code review and natural language features.

N

Novita

United StatesAI embeddings and model provider

Provides models and embeddings for code understanding and search.

C

Customer.io

United StatesCustomer communication

Sends product emails and lifecycle messages.

P

PostHog

United StatesProduct analytics

Captures usage analytics to help improve the product.

FAQs

Trust team
trust@kodus.io (SLA 2 business days)

Office hours: 9am to 6pm BRT