Security
Last updated September 23, 2026
This page explains how we protect trace data, manage credentials, and support vulnerability reporting.
1. How traces are redacted
Kensa redacts personal data and credentials from production traces before storage. Only the redacted version is retained.
- Detected secrets are removed: API keys, tokens, and private keys identified in traces are replaced before storage. Their original values are never retained.
- Stable aliases preserve context across traces: names, emails, phone numbers, and similar values are replaced with a stable per-project alias. Repeated values receive the same alias within a project, preserving context across traces while keeping the original values out of storage.
- Use trace and span IDs that are free of personal data; Kensa preserves these identifiers as-is for correlation with your own systems.
2. Scoped access and credentials
- Your data stays out of model training: trace content and any repository files sent to our model provider for issue detection or context drafts are not used to train models, ours or theirs.
- Repository access: when you request an initial context draft, Kensa reads selected repository files using a repository-scoped read token and sends their contents to its model provider. Repository access is read-only and scoped to the selected repository.
- Coding agent access: your coding agent connects over MCP with an OAuth grant scoped to a single project, valid for up to 30 days, and revocable at any time from Agent connections. Most of its tools are read-only; only reporting a deployed fix writes to Kensa, and every action is limited to the project the grant was issued for.
- Tracing credentials: a separate project API key authenticates trace ingest over TLS and can be rotated at any time without losing history, independent of any MCP grant.
- Langfuse credentials you provide are verified against your chosen region, encrypted in storage, and hidden after submission.
3. Retention
Redacted traces are retained according to your plan: 14 days on Free, 90 days on Pro, and a custom retention period on Enterprise. Deleting a project or account removes all its associated data.
4. Reporting a vulnerability
If you believe you've found a security issue in Kensa, email security@kensa.sh with details and we'll respond.