adense
← Back to Kadense

Legal

Privacy & cookies

Kadense is a security product, so we hold ourselves to the posture we measure. This page states plainly what we do and don't keep. It is written to be read, not to be hidden behind. It is not a substitute for legal advice.

In summary

The whole page in one table. Detail follows below.
WhatDo we keep it?For how long
Your source code Never Destroyed immediately after the run. The deletion is logged.
Supporting documents you attach Never Read for that single run and discarded. Only the filename is noted on the report.
Assessment reports Yes Scores, findings and their evidence quotes. Envelope-encrypted at rest.
Account & organisation data Yes While the account is active. Anonymised after a short grace period on deactivation.
Audit log Yes Tamper-evident and chained, so entries cannot be removed — only what the chain requires is retained.
Tracking & analytics cookies None Essential cookies only — session, CSRF, and your theme choice.
Sale or sharing of your data Never Not sold, not shared for advertising, not used to train models.

What we store — and what we never do

Your source code is never retained. When you run an assessment, your uploaded code is analysed inside an isolated, no-network sandbox and destroyed immediately afterwards. We keep the report of the run — scores, findings and their evidence quotes — never the code itself.

Supporting documents are never retained either. If you attach evidence for a contextual re-assessment, we read its text for that single run and discard it — only the report notes which documents were provided. Nothing you upload persists past the run.

We do keep the account and operational data needed to run the service: your organisation and user record, assessment history and reports, billing records, and a tamper-evident audit log. Sensitive fields (including your email and report contents) are envelope-encrypted at rest.

Cookies we use

We use essential cookies only — there is no tracking, analytics, or advertising. Because they are strictly necessary to provide the service, they don't require opt-in consent; we tell you about them for transparency.

Session / authenticationKeeps you signed in securely after login.
CSRF tokenProtects forms against cross-site request forgery.
Theme & notice acknowledgementRemembers your dark/light choice and that you've seen this notice.

Your rights

Under POPIA (and GDPR where it applies) you can access, correct, or request deletion of your personal information, and object to its processing. When an account is deactivated we anonymise its personal information after a short grace period, keeping only what the tamper-evident audit record requires. To exercise any of these rights, contact us below.

Contact

Questions about your data, or a request to exercise your rights — email support@collabor8.ai.