We get read access to systems that matter. This is how that access is bounded, what happens to the data we touch, and how we tell you when something goes wrong.
01Access model
Least privilege, read-only by default. We work through an identity we can see: single sign-on with hardware-key multi-factor authentication, per-engagement accounts, no shared logins, and no standing production write access — a change is applied by your engineer or through a session you approve. Every account is provisioned for one engagement and revoked at close; access reviews run monthly.
02Data we handle
Traffic traces, configurations, model artefacts, logs and metrics. We ask for sampled or synthetic traffic when the question can be answered that way, and we prefer aggregate metrics to raw payloads. Where raw requests are unavoidable, we tell you before they move, and we strip credentials and tokens from anything we store.
03Storage and encryption
TLS 1.2 or better in transit; AES-256 at rest on encrypted volumes and encrypted laptops. Secrets live in a managed vault, never in a repository or a chat message. Local scratch space on an engineer's machine is purged at engagement close.
04Our own environment
Managed endpoint detection on every machine, disk encryption enforced, password manager with unique generated credentials, hardware keys for every service, dependency scanning on our own repositories, and a documented incident runbook rehearsed twice a year.
05Sub-processors
Cloud infrastructure, an identity provider, a password manager and a vault. The list is available on request; adding one that touches client data means telling you first.
06Incident response
If we detect an incident affecting your data, we tell you within 72 hours of detection with what we know, what we have done and what we will do, then update at agreed intervals until close. We cooperate with your incident process and preserve forensic evidence.
07Evaluation and model safety
Quality gates run on your evaluation set inside your environment where the data cannot leave. A gate result is a report, not a training signal: your data does not train any model we use.
08Reporting a problem
Write security@kusukang.com. We acknowledge within one business day, we do not pursue researchers who act in good faith, and we would rather hear about a bug before a customer does. General questions: hello@kusukang.com.