run.in.your.vpcRun the proxy in your VPC.
Kurral ships as a containerized proxy you can run inside your own network. Only the findings and metadata you authorize ever leave. The image runs as a non-root user with healthchecks built in.
Kurral sees your most sensitive prompts, tool calls, and model output. We treat them like the secrets they are. Below: what's shipped, what's in flight, and how to verify both.
Every claim below maps to code in our repository. Ask and we'll walk you through the implementation.
run.in.your.vpcKurral ships as a containerized proxy you can run inside your own network. Only the findings and metadata you authorize ever leave. The image runs as a non-root user with healthchecks built in.
retention.you.chooseWorkspaces pick none, metadata, or full trace retention. Per-request headers can tighten retention but never loosen it. Default is metadata-only.
provider.keys.never.persistedAnthropic, OpenAI, and Google API keys are stripped from request bodies at the edge before anything reaches storage or logs.
workspace.scoped.readsEvery dashboard query is scoped to the authenticated workspace. No cross-workspace data access at any layer.
sso.mfa.managedLogin, MFA, and social SSO are fully managed. Enterprise SAML / OIDC is on the roadmap.
no.trace.body.analyticsTrace contents never leave for analytics, session replay, or marketing tools. Product telemetry covers UI events only.
Most security testing tools force your traffic through their cloud. We don't — prompt traces stay where you decide they stay.
Multi-tenant cloud, fully managed. Best for design partners running their first scan this week.
best for · fast onboardingContainer image runs in your VPC, next to the agent under test. Only signed findings and the metadata you opt into ever egress to Kurral.
best for · regulated data (PHI / PCI / MNPI)Library mode. Scenario engine and verdict logic run in-process. auto_sync=False disables phone-home; we're making that the default for the air-gapped build.
Policy commitments, written into our DPA and Terms. They're as binding as the code we ship.
no training on you.No customer prompt, completion, tool I/O, or finding is ever used to train, fine-tune, or evaluate a Kurral-owned model.
no cross-customer learning.We never reuse one customer's adversarial run to seed scenarios for another. Public scenarios are documented and versioned. Private scenarios stay tenant-scoped.
severity moves get published.When we change how severity is scored, we publish what moved and why.
disclosure-first.We disclose breaches with timelines. We don't deflect.
good security tools earn trust the same way good auditors do — with disclosure, not deflection.Every certification below is verifiable. We don't claim what we don't hold. Email security@kurral.com for the underlying reports and timelines.
We treat reports the way we expect customers to treat ours — acknowledged within 24 hours, fixed before disclosed.
security@kurral.com (PGP key — coming Q2) legal@kurral.com (DPA / privacy) arvind@kurral.com (founder)
disclosure-first. always.We use cookies to understand how Kurral is used and to remember your preferences. Details in the privacy policy.