Security at Kurrens
We protect customer data with encryption in transit, least-privilege access, and zero data retention for inference content.
How we protect data
- TLS 1.2+ for all traffic to our website, console, and API.
- Prompts and completions are processed in memory only and excluded from logs (Data Policy).
- API keys are stored as salted hashes and shown only once at creation.
- Role-based, least-privilege access to production with multi-factor authentication.
Reporting vulnerabilities
If you believe you've found a security vulnerability in Kurrens, emailsupport@kurrens.ai with the subject line "Security report", steps to reproduce, and any proof-of-concept. We'll acknowledge your report and keep you updated while we investigate.
Guidelines
- Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
- Only access data that belongs to you; stop and report if you encounter anyone else's data.
- Give us reasonable time to fix the issue before disclosing it publicly.
- You must be at least 18 and not located in a sanctioned country or listed on a sanctions list.
Out of scope
Jailbreaks, prompts that induce harmful or policy-violating output, and model hallucinations (for example, a model claiming to access systems or secrets) are not security vulnerabilities. Report model misuse tosupport@kurrens.ai with the subject line "Abuse report".