Platform Security
KLUE processes extremely sensitive data: your code, your configurations, and the vulnerabilities we find. Here is exactly how the platform protects it.
Last updated: August 2026
Every scan runs in an isolated, ephemeral sandbox. Findings are stored in your tenant, isolated by row-level security, and encrypted in transit and at rest. Client data is never used to train our models, and for sensitive workloads we can run models so that your data never leaves a controlled environment.
You configure a scan in the dashboard and our API checks your plan quota and concurrency limits.
A dedicated sandbox is created each scan runs inside an isolated, ephemeral virtual machine. Source code is cloned using short-lived tokens that are scrubbed after use.
Security engines run inside the sandbox KLUE performs cloud/M365 audits, source code review, live app/API testing, autonomous testing, or threat intelligence collection as configured.
An AI engine reasons over the work KLUE uses large language models to plan, select tools, and interpret results. Relevant context is sent to a model provider for processing, with credential redaction applied first.
Findings stream to storage results, logs, and reports are written to our database and object storage, isolated to your tenant by row-level security.
The sandbox is destroyed when the scan finishes, the ephemeral environment and its working copy of your data are torn down. Reports and findings remain in your workspace until you delete them or your retention period ends.
See our subprocessors, privacy policy, and engagement data handling.