Security

Built to be trusted with your work

codai sits between your tools and frontier models. That position comes with obligations: EU hosting, encryption everywhere, no training on your prompts by default, and a disclosure process that takes reports seriously.

  • Data stays in the EU

    The gateway, database and logs run on Google Cloud in europe-west1 (Belgium). Model providers we route to operate in EU regions under data-processing agreements.

  • Encrypted in transit and at rest

    TLS 1.2+ on every connection. Databases, backups and secrets are encrypted at rest with keys managed in Cloud KMS; provider credentials are envelope-encrypted.

  • No training on your prompts — opt-in only

    Your prompts and model outputs are never used to train codai models unless you switch on "Use my data to improve codai". It is off for every new account and can be withdrawn at any time.

  • Keys are hashed, rotation is graceful

    API keys are stored only as salted hashes; we cannot read them back. Rotating a key keeps the previous one valid for 24 hours so deploys never break mid-rollout.

  • Passkeys and TOTP on auth.codai.ro

    Sign-in runs on a dedicated OpenID Connect identity service. Passkeys (WebAuthn) and authenticator-app codes are supported; sessions can be revoked per device from the console.

  • Export and delete on your terms

    Download everything we hold about you from the console. Account deletion is self-service, takes effect immediately and has a 7-day grace window before backups are purged.

Responsible disclosure

Found a vulnerability?

Tell us before you tell anyone else. Send the details — affected endpoint, reproduction steps, impact — to our security address. We acknowledge every report within three business days, keep you informed while we fix it, and credit you if you wish.

We follow a 90-day coordinated disclosure window: you may publish once a fix is live or 90 days after your report, whichever comes first. Please do not access other users' data or degrade the service while testing.

Email [email protected]