KORPS.AI Sign in

Trust

Security

Version 0.1 · Drafted August 28, 2026 · Describes the platform as built on that date

What we do not claim

Korps holds no SOC 2 report, no ISO 27001 certificate, no PCI DSS attestation and no HIPAA business associate agreement. We do not have an independent audit, and we will not say we do until one exists.

Do not put protected health information, payment card data or government identity documents into Korps.

The architecture is deliberately kept capable of private, isolated runtime and model deployments, which is a prerequisite for a future regulated configuration. That is a design property, not a compliance claim.

This is an engineering draft. It describes the build as inspected on the date above and has not yet been reviewed by counsel or by an independent security assessor. Both reviews are required before it is published as a formal statement.

This page describes controls that are actually implemented. Anything planned is labelled as planned.

1. Accounts and sessions

2. Rate limiting and abuse controls

3. Tenant isolation

4. Infrastructure pairing

5. Transport and hosting

6. Provider credentials

7. Logging

8. Usage limits as a safety control

Every workspace is metered against a token allowance for a rolling window. When the allowance is reached, metered work is refused rather than continuing silently. Metering stores token counts, provider and model names, not prompt content.

9. Agent authority

Agents act with the authority you give them. Korps treats a defined set of operations as high risk and outside the scope of any auto-approval setting, including force-push and history rewrite, destructive deletes, removing backups, credential exposure or movement, privilege escalation and payment actions. See the Acceptable Use Policy.

10. Known gaps and what is planned

Stated plainly so nobody has to guess:

11. Reporting a vulnerability

Send findings to security@korps.ai (mailbox to be confirmed before publication). Please include steps to reproduce, the affected endpoint or page, and what you were able to access.

Good-faith safe harbour

If you follow these rules we will not pursue or support legal action against you for the research:

We aim to acknowledge a report within 3 business days and to give a remediation view within 14 days. Those are goals, not a contractual service level. We do not operate a paid bug bounty today.