PRIVACY POLICY

Zero-Retention Privacy Shield

Kronumos is committed to the confidentiality, integrity, and intellectual property protection of developers and engineering organizations. This policy outlines our data processing standards and Zero Code Retention architecture.

1. Core Architectural Invariant: Zero Code Retention (ZCR)

Source code is proprietary intellectual property. Unlike conventional consumer AI platforms:

Zero Persistent StorageThe Kronumos Edge Gateway does not write, log, index, or persist user prompts, code snippets, diffs, or repository contents to any database or long-term cloud storage.
In-Memory Ephemeral ExecutionInference requests are executed strictly in volatile memory within isolated runtimes and immediately purged from memory once the response stream terminates.
No Model Training on User DataUser code, test execution traces, and debugging inputs are never utilized to train, fine-tune, or adapt foundation or secondary models.

2. Secret Redaction Pipeline

To prevent inadvertent credential leakage, Kronumos operates a multi-stage sanitization pipeline:

  • Client-Side Sanitization: The local CLI kernel applies high-throughput pattern analysis to redact AWS keys, GitHub tokens, JWTs, API keys, and private SSH keys.
  • Edge Gateway Sanitization: As defense-in-depth, edge gateways execute regular expression scrubbers, replacing detected credentials with redacted tokens before inference forwarding.

3. Minimal Data Processed

We adhere strictly to data minimization principles. The only network metadata processed includes:

  • Connecting IP Address: Used solely for edge rate limiting (sliding-window anti-hammering) and DDoS mitigation. Counters reside exclusively in volatile edge memory.
  • Request Metadata: Content length and HTTP header metadata required for CORS enforcement and request routing.
  • API Authentication Headers: Optional Bearer keys used to verify request authorization and tier limits.

4. Local-First & Sovereign Deployments

For organizations operating under strict confidentiality, defense, or banking requirements:

Kronumos supports 100% offline local inference execution via private GPU clusters and on-premise hardware, transmitting zero telemetry or data packets across external networks.

For privacy inquiries or data protection communications, contact: daffa@kronumos.com