Trust Center

What we do with your data, and what we don't.

BLAZLE sits in the path of your most sensitive traffic. Here is how we protect it.

Last updated October 1, 2026

We run on BLAZLE

We secure our own code and our own AI with BLAZLE, with no exceptions.Every pull request to BLAZLE and to every repository across Kolerr Lab, Inc. is scanned by the BLAZLE GitHub App before merge. BLAZLE's own AI Copilot, a full MCP server with access to rules, incidents, API keys and policies, runs through the same interceptor as customer traffic.

Our repositories
Every pull request across BLAZLE and Kolerr Lab is scanned before merge.
Copilot prompts
Inspected by BLAZLE before they reach the AI model.
Permissions
Every tool call is limited to the caller's own role.
Tool calls
Intercepted like customer traffic. If BLAZLE would block it for you, it blocks its own Copilot.
Changes
Held for human approval; destructive actions need a second approver.
Evidence
Every proposal, decision and execution is written to the tamper-evident audit log.

Your data

Every prompt, command and diff is inspected inside BLAZLE. Detection never sends your payload to a third-party AI service, and we never use your data to train models.

Allowed requests
Not stored. Only aggregate usage counts are kept for quota and billing.
Blocked requests
Kept as an investigation record, with detected secrets masked.
Code scan findings
Secret values are masked before they are stored.
Retention
7 days (Hacker), 30 (Pro Developer), 90 (Business), 365 (Enterprise).
Deletion
On request; personal data is purged within 30 days.

Data protection

In transit
Encrypted on every connection.
At rest
Sensitive credentials and secrets are encrypted at rest.
Passwords
Hashed with bcrypt (cost factor 12), with a per-password salt.
API keys & tokens
Stored only as one-way hashes and shown once at creation.

Identity & access

Sessions
Short-lived, not readable by scripts, revocable instantly.
Two-factor
Authenticator-app 2FA with single-use backup codes.
Single sign-on
OpenID Connect SSO with domain restriction.
Provisioning
SCIM 2.0 user lifecycle from your identity provider.
Roles
Owner, Admin, Security Analyst, Member, Viewer. Enforced server-side on every request.
Copilot actions
Changes wait for human approval; destructive ones need a second approver.

Workspace isolation

Each workspace's data is isolated at both the application and the database layer. Even if one layer were bypassed, the other still prevents one customer from reading or changing another customer's data.

Audit & evidence

Every audit event is written to a tamper-evident, cryptographically chained log: any edit or deletion breaks the chain, and admins can verify its integrity from the dashboard at any time.

Export an evidence bundle (audit integrity, retention, access review, active policy), a MAS-TRM package, or SIEM-ready logs.

Compliance

BLAZLE is built to align with MAS-TRM: every finding is scored on its Likelihood × Impact matrix. The tamper-evident audit log, retention controls, access reviews and one-click evidence bundles are designed to support your SOC 2, ISO 27001 and MAS-TRM audits.

Engineering assurance

Memory safety
The core service is built in a memory-safe language.
Dependencies
Every build is gated on known-vulnerability and licence checks.
Security reviews
Regular in-depth reviews of authorization, isolation, secrets handling and abuse protection.
Testing
Integration and failure-mode testing against production-equivalent infrastructure.

Vulnerability disclosure

Found a security issue? Email security@blazle.io with steps to reproduce. Please give us reasonable time to fix it before disclosing publicly, and avoid accessing data that is not yours. We do not take legal action against good-faith research.

Related: Privacy Policy · Terms of Service