Security

Security at Korden

Last updated 10 June 2026 · Early access

Korden is built so that the most sensitive thing you own — your source code — stays under your control. The architecture is local-first, and the few cloud features are opt-in and protected in transit.

Core principle: your code runs and stays on your machine. Korden observes and orchestrates locally; it doesn't ship your repositories to our servers to function.

Local-first by default

Installers & updates

Updates are delivered through a cryptographically signed auto-update channel, so the app verifies each update genuinely came from us and hasn't been tampered with, and builds are produced by an automated CI pipeline rather than by hand. Authenticode signing of the Windows installer is in progress — until it lands, Windows may show an “unknown publisher” notice on first run.

Credentials

Your model logins and API keys are stored locally on your device and used to talk to your chosen provider. We don't collect or store your model API keys on Korden's servers.

Accounts & payments

Responsible disclosure

Found a vulnerability? We want to hear from you. Email support@kordenhq.com with the subject “Security disclosure” and steps to reproduce. Please give us a reasonable window to investigate and fix before any public disclosure — we'll keep you in the loop.

Korden is in early access. We're hardening continuously and will expand this page (and our formal practices) as we grow. Questions? support@kordenhq.com.