Security and data
Where your data lives, how runs are isolated, what model providers see, retention and the DPA.
kanman works on your source code. These pages explain plainly what that means for your data and your compliance work.
Hosting and data residency
Where kanman runs, where your data is stored, and how to keep code execution on your own infrastructure.
Sandbox and secrets
How runs are isolated, what the coding agent may touch, and how kanman keeps secret values out of runs.
What model providers see
Which language model providers receive data during a run, what they receive, and how to use your own contract.
Retention and deletion
How long kanman keeps runs, evidence and audit entries, and what happens when you delete a team or a workspace.
DPA and subprocessors
The data processing agreement for kanman, where to find the current list of subprocessors, and how changes are announced.