Trust Center
Security & compliance
One place for how Korbition protects data across every product: security posture, sub-processors, data residency, and the legal framework.
Security posture
- Encryption — TLS 1.3 in transit, AES-256 at rest for credentials, run records, and stored content.
- Tenant isolation — strict logical isolation at the data layer; cross-tenant access is blocked.
- Least privilege — permission-scoped execution; actions run as their author and are withheld when authority cannot be established.
- Vulnerability handling — automated scanning, coordinated disclosure, Atlassian Security Bug Fix Policy timelines. Report to [email protected] (acknowledged within 2 business days).
- Honest receipts — run receipts are sealed at rest and report what actually executed.
Data residency
Primary region is EU (Frankfurt). Data residency is fixed to the deployment's region — a tenant is only served by a deployment whose residency it is allowed on. There is no silent cross-region movement.
Sub-processors
| Role | Provider | Region / notes |
|---|---|---|
| Compute & container hosting | Fly.io, Inc. | Frankfurt, EU primary |
| Database & encrypted storage | Neon, Inc. (on AWS) | Frankfurt, EU primary |
| AI inference (default) | Amazon Web Services (Bedrock) via OpenRouter | EU (Ireland), Zero Data Retention |
| Edge & network protection | Cloudflare, Inc. | DNS, DDoS, TLS |
Legal framework
- Privacy Policy — company-wide (Part A) + per-product (Part B)
- Terms of Service — §§1–10 + per-product schedules
- EULA — license, warranty, liability + per-product schedules
- Impressum — provider identification (Germany)
- security.txt — vulnerability disclosure contact
Each product gets its own Privacy Part B section and Terms / EULA schedule. New products are added as they launch; company-wide sections always apply too. Currently published: Rulekestra.
Atlassian Marketplace (Rulekestra)
- Rulekestra runs on Atlassian Forge; scopes are visible on the Marketplace listing before install.
- Billing, renewals, and refunds are handled by Atlassian under Atlassian's Marketplace Terms of Use.
- We follow Atlassian's Cloud Security Requirements and Security Bug Fix Policy.
Contact
- Security reports — [email protected]
- Privacy requests — [email protected]
- Legal — [email protected]
- Support — [email protected]