Trust Center
What we do with your data, and what we don't.
BLAZLE sits in the path of your most sensitive traffic. Here is how we protect it.
Last updated October 1, 2026
We run on BLAZLE
We secure our own code and our own AI with BLAZLE, with no exceptions.Every pull request to BLAZLE and to every repository across Kolerr Lab, Inc. is scanned by the BLAZLE GitHub App before merge. BLAZLE's own AI Copilot, a full MCP server with access to rules, incidents, API keys and policies, runs through the same interceptor as customer traffic.
- Our repositories
- Every pull request across BLAZLE and Kolerr Lab is scanned before merge.
- Copilot prompts
- Inspected by BLAZLE before they reach the AI model.
- Permissions
- Every tool call is limited to the caller's own role.
- Tool calls
- Intercepted like customer traffic. If BLAZLE would block it for you, it blocks its own Copilot.
- Changes
- Held for human approval; destructive actions need a second approver.
- Evidence
- Every proposal, decision and execution is written to the tamper-evident audit log.
Your data
Every prompt, command and diff is inspected inside BLAZLE. Detection never sends your payload to a third-party AI service, and we never use your data to train models.
- Allowed requests
- Not stored. Only aggregate usage counts are kept for quota and billing.
- Blocked requests
- Kept as an investigation record, with detected secrets masked.
- Code scan findings
- Secret values are masked before they are stored.
- Retention
- 7 days (Hacker), 30 (Pro Developer), 90 (Business), 365 (Enterprise).
- Deletion
- On request; personal data is purged within 30 days.
Data protection
- In transit
- Encrypted on every connection.
- At rest
- Sensitive credentials and secrets are encrypted at rest.
- Passwords
- Hashed with bcrypt (cost factor 12), with a per-password salt.
- API keys & tokens
- Stored only as one-way hashes and shown once at creation.
Identity & access
- Sessions
- Short-lived, not readable by scripts, revocable instantly.
- Two-factor
- Authenticator-app 2FA with single-use backup codes.
- Single sign-on
- OpenID Connect SSO with domain restriction.
- Provisioning
- SCIM 2.0 user lifecycle from your identity provider.
- Roles
- Owner, Admin, Security Analyst, Member, Viewer. Enforced server-side on every request.
- Copilot actions
- Changes wait for human approval; destructive ones need a second approver.
Workspace isolation
Each workspace's data is isolated at both the application and the database layer. Even if one layer were bypassed, the other still prevents one customer from reading or changing another customer's data.
Audit & evidence
Every audit event is written to a tamper-evident, cryptographically chained log: any edit or deletion breaks the chain, and admins can verify its integrity from the dashboard at any time.
Export an evidence bundle (audit integrity, retention, access review, active policy), a MAS-TRM package, or SIEM-ready logs.
Compliance
BLAZLE is built to align with MAS-TRM: every finding is scored on its Likelihood × Impact matrix. The tamper-evident audit log, retention controls, access reviews and one-click evidence bundles are designed to support your SOC 2, ISO 27001 and MAS-TRM audits.
Engineering assurance
- Memory safety
- The core service is built in a memory-safe language.
- Dependencies
- Every build is gated on known-vulnerability and licence checks.
- Security reviews
- Regular in-depth reviews of authorization, isolation, secrets handling and abuse protection.
- Testing
- Integration and failure-mode testing against production-equivalent infrastructure.
Vulnerability disclosure
Found a security issue? Email security@blazle.io with steps to reproduce. Please give us reasonable time to fix it before disclosing publicly, and avoid accessing data that is not yours. We do not take legal action against good-faith research.
Related: Privacy Policy · Terms of Service