Privacy Policy

Effective August 21, 2026

Who we are

Korrali Trust ("Korrali", "we", "our") is operated by Korrali LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, United States. This policy explains what data we collect when you use trust.korrali.com.

Data we collect

  • Account data: Name and email address when you sign up via Google OAuth or an email sign-in link.
  • Your knowledge base: The security, compliance and product documentation you upload or enter — policies, control descriptions, prior questionnaire answers and supporting evidence. This is the substance of the product and is stored so it can be reused across questionnaires.
  • Questionnaires you process: Files you upload for parsing, the questions extracted from them, and the answers generated or edited.
  • Trust page content: Anything you choose to publish to a public trust page is, by design, publicly accessible.
  • Billing data: Subscription state and payment records held by Stripe. We never see or store card numbers.
  • Product analytics and errors: Usage events and crash reports, used to operate and improve the service.

Connected AWS accounts

If you connect an AWS account, you create an IAM role in your own account and give us its ARN and an external ID. We assume that role to read security-posture configuration so it can populate your control dashboard.

What we read: IAM users, access keys, MFA devices and the account password policy; S3 bucket listings with their encryption and public-access status; CloudTrail trails and their logging status; and GuardDuty detector configuration.

Every one of these calls is read-only. We do not create, modify or delete anything in your AWS account, and we do not read the contents of your S3 objects — only whether a bucket is encrypted and whether it is publicly exposed. You can revoke access at any time by deleting the IAM role on your side, which takes effect immediately.

AI processing — please read this one

Generating answers requires sending relevant excerpts of your knowledge base and the questions being answered to third-party AI providers. We currently use Anthropic, OpenAI and Google. Content leaves our infrastructure to reach them.

Answers are grounded in your own knowledge base and cite the source they came from, rather than being generated freely. Generated answers are drafts for your review — you remain responsible for what you send to a customer or auditor.

If your security documentation is sensitive enough that third-party AI processing is unacceptable to you, this product is not a good fit, and we would rather you knew that before uploading anything.

How we use your data

  • To parse questionnaires and draft answers from your knowledge base.
  • To maintain your control dashboard and any trust page you publish.
  • To authenticate you and manage your subscription.
  • To monitor service health, diagnose failures and improve the product.

We do not sell your data, and we do not use your knowledge base to train our own models.

Sub-processors

  • Anthropic, OpenAI, Google — AI answer generation.
  • Amazon Web Services — read-only posture checks against any AWS account you connect.
  • Stripe — payments and subscription billing.
  • Resend — transactional and sign-in email.
  • Google — OAuth sign-in.
  • PostHog — product analytics.
  • Sentry — error and performance monitoring.
  • Amazon Web Services — hosting and data storage.

Data retention

Your knowledge base and questionnaire history are retained for as long as your account is active, because the product's value depends on reusing them. You can delete individual items at any time. On account deletion we remove your content within 30 days, except where we must retain billing records to meet legal and tax obligations.

Security

Data is encrypted in transit with TLS and at rest. Access to production systems is limited to personnel who need it to operate the service. No system is perfectly secure, and we will not pretend otherwise — if a breach affects your data we will tell you.

Your rights

You may request access to, correction of, export of, or deletion of your data. Depending on where you live you may have additional rights under GDPR, UK GDPR or CCPA, including the right to object to processing and to lodge a complaint with your supervisory authority. Email us and we will action it.

Changes to this policy

If this policy changes materially we will update the effective date above and notify account holders by email.

Contact

Privacy questions: privacy@korrali.com · Security matters: security@korrali.com · Or write to: Korrali LLC, 30 N Gould St, Ste N, Sheridan, WY 82801, USA.