Skip to document
Koreshield
ProductDemoHow It WorksResearchPricingFAQCompany
Go to workspace
ProductDemoHow It WorksResearchPricingFAQCompanyGo to workspace
Privacy

Privacy Policy

How we handle account data, security evidence, and the content that passes through Koreshield scans.

Effective 8 October 2026Koreshield Labs Ltd · Company No. 17057784
Legal documentsPrivacy PolicyTerms of ServiceData Processing AgreementLegal and privacy enquiriesReport a security incident
01

Who we are and when this policy applies

Koreshield Labs Ltd ("Koreshield", "we", "us" or "our") is incorporated in England and Wales under company number 17057784. Our registered office is 3rd Floor, 86–90 Paul Street, London, EC2A 4NE. We provide security infrastructure for AI applications, including input, retrieved-context, and proposed-action scanning.

This policy explains our processing as a controller when you visit our website, create or administer an account, use our workspace, purchase a plan, or contact us. When we scan data for a customer, we generally act as that customer's processor and our Data Processing Agreement governs that processing.

02

Data we collect

The data we collect depends on how you use Koreshield.

  • Account and identity data, such as name, work email, company, sign-in provider identifiers, and one-way password hashes where password sign-in is used.
  • Workspace and service data, including API-key hashes, configuration, policy settings, usage counts, scan decisions, timestamps, request or scan identifiers, severity, confidence, and related security evidence.
  • Billing and subscription data supplied by our billing provider. Koreshield does not store full payment-card numbers.
  • Technical and security data, such as IP address, browser and device information, authentication events, error records, and operational logs.
  • Communications you send to us, including support, legal, security, and partnership correspondence.
03

Scan content and privacy-by-default storage

Input text, retrieved documents, tool names, action arguments, and related context may contain personal data. We process that content to return a security decision. The default hosted workspace mode is hash-only: raw scan content is processed transiently and is not written to the event record. The stored record contains hashes and decision evidence needed to operate and audit the service.

A customer may explicitly enable encrypted content storage for its workspace. In that mode, selected review content is encrypted before storage and retained under the workspace's configured event-retention period. Customers are responsible for choosing a mode and retention period appropriate to their own lawful basis and notices.

Koreshield does not use customer scan content to train generative models, sell personal data, or serve advertising. Our direct scan endpoints do not send raw scan content to generative-model providers.

04

How and why we use data

We process personal data only where we have a lawful basis and for defined operational purposes.

  • To create accounts, authenticate users, provide scans, apply policies, maintain audit evidence, and administer subscriptions, on the basis of contract.
  • To secure, monitor, troubleshoot, and improve the reliability of Koreshield, on the basis of our legitimate interests in operating a safe service.
  • To respond to support, privacy, legal, and security requests, on the basis of contract, legitimate interests, or legal obligation as applicable.
  • To process payments, keep required business records, and comply with tax, company, sanctions, and data-protection law, on the basis of contract or legal obligation.
  • To send marketing only where permitted by law. You may opt out at any time.
05

Service providers and disclosures

We use a limited set of providers to operate Koreshield: Hetzner for primary hosted application and database infrastructure; Cloudflare for network, DNS, edge security, Turnstile, Workers, and operational log storage; Postmark for transactional email; Polar for subscription billing; and Google or GitHub when a user chooses those optional sign-in methods.

A customer's own model provider remains the customer's provider. We may disclose data where required by law, to protect rights or service security, or as part of a corporate transaction subject to appropriate confidentiality and data-protection safeguards. We do not sell personal data.

06

International transfers

Koreshield's primary hosted application and database infrastructure is in Germany. Some service providers may process limited account, network, support, billing, or authentication data in other countries.

Where UK or EEA personal data is transferred internationally, we use an applicable lawful transfer mechanism, such as an adequacy regulation or recognised contractual safeguards, together with proportionate technical and organisational measures.

07

Retention and deletion

Workspace event retention is configurable from 1 to 365 days, subject to plan and contract. Current standard plan defaults are 7 days for Starter and 30 days for Growth. Hash-only mode does not persist raw scan content; encrypted content, when enabled, follows the associated event's retention period. Operational edge logs are ordinarily retained for 30 days.

We keep account, security, support, billing, and legal records only for as long as needed for the purpose collected, to resolve disputes, or to meet legal obligations. When data is deleted from active systems, restricted recovery copies may remain until those copies are retired; they are isolated from routine processing and used only for recovery, security, or legal requirements.

08

Security

We use encrypted transport, one-way credential and API-key hashing, tenant-scoped authorisation, restricted production access, security logging, and tested deployment controls. Optional stored review content is encrypted. No service can guarantee absolute security, and customers must protect their credentials and keep API keys out of browser or mobile client code.

Report suspected vulnerabilities or security incidents to hello@koreshield.ai with the subject “Security incident”.

09

Your data-protection rights

Depending on the law that applies, you may have rights to access, correct, erase, restrict, object to, or obtain a portable copy of your personal data, and to withdraw consent where processing is based on consent. Email hello@koreshield.ai to exercise a right. We may need to verify your identity.

If Koreshield processes your data for one of our customers, please contact that customer first; we will assist them under our DPA. You may also complain to the UK Information Commissioner's Office or another competent supervisory authority.

10

Cookies, children, and changes

We use strictly necessary browser storage and cookies for authentication, security, and service operation. Koreshield is a business service and is not directed to children.

We may update this policy as the service, providers, or law changes. We will post the revised effective date and provide additional notice where a material change or applicable law requires it.

11

Contact

Privacy, data-subject, legal, and security enquiries: hello@koreshield.ai. Postal address: Koreshield Labs Ltd, 3rd Floor, 86–90 Paul Street, London, EC2A 4NE, United Kingdom.

Koreshield

Security boundaries for AI support workflows.

hello@koreshield.ai

Product

Security BoundariesHow It WorksInteractive DemoPricingFAQ

Company

AboutTeamCareersContact

Resources

ResearchDocumentationBlogFAQ

Legal

Privacy PolicyTerms of ServiceData Processing AgreementSecurity contact
© 2026 Koreshield. All rights reserved.Koreshield Labs Ltd. · Incorporated in England & Wales · Co. No. 17057784