K
Kerno
← Back

Security & Data Flow

Last updated: April 24, 2026

We market Kerno as "your data, your server." This page shows exactly what that means — what stays on your machine, what leaves it, and why.

Where your data actually lives

When you run Kerno on your infrastructure, the following all stay on your server and never reach us:

We have no access to any of this. We don't run a database on your behalf; we don't back your data up to our cloud; we don't ship telemetry containing your data.

What leaves your server (and why)

Three things leave your server in the normal course of operation:

Secrets at rest

Authentication

What we log on our servers

The marketing site at getkerno.ai logs:

We do not log anything from running Kerno instances. If we ship crash reporting or opt-in telemetry in the future, it will be clearly disclosed and disabled by default.

Network posture

Dependencies and supply chain

Reporting a vulnerability

If you find a security issue, please email security@getkerno.ai with details. We'll acknowledge within 72 hours and work with you on disclosure timing. We don't run a formal bug bounty yet, but genuine findings get a thank-you, a public credit (if you want it), and we'll credit you in the changelog.

What we haven't formalised yet (honest list)

If these gaps are blockers for your organisation, please get in touch — a consulting engagement can include custom security work and formal documentation.