KopernikLabs
ENTERPRISE TRUST GUARANTEES

Your code modernizes.
Your IP stays yours.

Kopernik Labs handles mission-critical legacy repositories, so trust is not a marketing section — it is the operating contract. Every guarantee below is a citable commitment: each carries a register ID, a one-line clause, and the mechanism that enforces it.

Guarantee ZDR-01

1. Zero Data Retention & No-Training SLA

Commitment — ZDR-01

“Customer source code is never used to train any AI model — including Claude Sonnet 5.5 and Claude Opus 5.5 — and is purged from working memory when the session ends.”

Zero-retention model endpoints

All foundation-model inference runs through Anthropic commercial endpoints under Zero Data Retention. Prompts and completions are not stored by the provider and never enter training corpora.

Session-scoped memory only

Your AST index, schemas, and type definitions live in prompt-cache working memory for the duration of the engagement session. When the session ends, the cache expires and the memory is cleared. There is no cross-customer or cross-engagement context carry-over.

Deliverables land in your repo, not ours

Generated pull requests, verification logs, and AST reports are pushed to your Git remote. We retain no copies of proprietary code after hand-off.

Guarantee SBX-02

2. Ephemeral Isolated Sandboxes

Commitment — SBX-02

“Every code transformation and test run executes inside a single-use, isolated Docker sandbox that is destroyed immediately after the job completes.”

One container per job

Sandboxes are never reused and never shared between customers. Each migration run gets a fresh container image, and the container is torn down — filesystem included — the moment verification finishes.

Network-isolated by default

Sandbox containers run with no outbound network access. The only egress permitted is an authenticated push of verified pull requests to your own Git remote.

Memory-backed workspaces

Transformed code is staged on ramdisk-backed volumes. Working copies never touch persistent disks we control, so there is nothing to leak, subpoena, or accidentally retain.

Guarantee NDA-03

3. Bilateral Mutual NDA & IP Ownership

Commitment — NDA-03

“A bilateral mutual NDA is executed before any code review begins, and 100% of generated refactor and pull-request code is owned by the customer.”

Mutual by default

The NDA protects both directions: your proprietary code, architecture, and roadmap, and our migration tooling and methodology. Either party can initiate the standard agreement from the workspace before repository access is granted.

Full IP assignment

All refactor output, synthesized tests, type definitions, and pull requests are delivered as work made for hire. You own them outright — no license-back, no residual rights, no reuse claims from us.

No portfolio leakage

We do not reference, screenshot, or publish customer code — not even anonymized fragments — without explicit written consent.

Guarantee ENC-04

4. Encryption & Access Control

Commitment — ENC-04

“All data is encrypted with TLS 1.3 in transit and AES-256 at rest, and every component operates under least-privilege access.”

TLS 1.3 everywhere

Every hop — browser to application, application to Firestore, sandbox to Git remote — is secured with TLS 1.3. Legacy protocol versions are disabled at the edge.

AES-256 at rest

Databases, object storage, and backups are encrypted at rest with AES-256, with managed key rotation on the underlying cloud infrastructure.

Least privilege, enforced in rules

Firestore is configured zero-trust: every collection denies by default, documents are readable only by their owning account, and write operations are locked down by validated server-side paths. Service accounts are scoped per function and hold no standing administrative access. Secrets live in scoped environment variables — never in the repository.

Control Matrix & Verification

Summary register for procurement and audit review. Each control traces to the guarantee clause that governs it.

ControlEnforcement MechanismClause
Model training on customer codeZero Data Retention endpoints + contractual no-training SLAZDR-01
Cross-tenant contaminationSingle-use, network-isolated Docker sandbox per jobSBX-02
Confidentiality before accessBilateral mutual NDA executed pre-onboardingNDA-03
Ownership of deliverablesWork-for-hire IP assignment, full transfer to customerNDA-03
Data in transitTLS 1.3 on all edges, legacy ciphers disabledENC-04
Data at restAES-256 with managed key rotationENC-04
Storage accessZero-trust Firestore rules, default-deny, owner-scoped readsENC-04
Secrets handlingScoped environment variables, excluded from version controlENC-04

Live today: encryption, zero-trust storage rules, least-privilege service accounts, and the NDA workflow are enforced in production. Sandbox and retention controls operate as described on every pilot repository onboarded during the private beta — see the architecture specification for the full engineering detail.

Security & Compliance Escalation

Need the signed NDA template, a DPA, sub-processor list, or a walkthrough of these controls with your security team? Contact founder & engineering lead Emre Bekir directly — audit requests are answered with priority.

bekiremre@koperniklabs.com →Response within one business day
© 2026 Kopernik Labs. All rights reserved.