Skip to content
Trust

Security

Where your data sits, what our software does with it, and what we do not yet hold.

Last reviewed 3 September 2026.

It runs on your infrastructure

Every system on our solutions page can run on your own server. That is the default rather than an upgrade. When it runs on your hardware your data stays there, and the backup you take is one we cannot read.

Nothing phones home

What we ship carries no usage tracking, no crash reporting back to us, and no silent updates. Where we started from software that did have telemetry, we removed it before shipping.

Stored credentials

Our desktop clients protect saved credentials with the operating system's own key store, so a copied settings file is useless on a different machine.

Where an AI model is involved

Some of what we build reads documents with an AI model. Which model, where it runs, and what may be sent to it are decided per project and written into the agreement before any document leaves your environment. We do not promise a particular provider arrangement on this page. We show you exactly what leaves, and we agree it with you first.

What we do not hold

We are not ISO 27001 certified and we hold no SOC 2 report. We are two engineers, and we would rather say so than let you assume otherwise. If your procurement requires either, tell us early and we will give you a straight answer about whether we can meet it.

Reporting a weakness

Found something wrong in anything we built? Write to info@codentra.net. We will confirm within one business day and tell you what we are doing about it.