Security & privacy
Your code, your rules
Privacy isn't a feature we bolt on — it's the reason konnos exists. Private by default, open to audit, no lock-in, and locked down on every connection.
No lock-in
Plain Git — yours to export, any time
It's plain Git underneath. Every repository, every byte of LFS, every backup is yours to clone, push, and export whenever you want. Staying with konnos is a choice, never a trap — your code is never held hostage.
Private by default
Closed until you decide otherwise
Every repository starts private. Nothing is visible to anyone — not other users, not search engines, not us beyond what's needed to run the service — until you explicitly choose to open it. Exposure is always a deliberate act, never an accident.
Transparency
Open-source and auditable
konnos is built in the open. You don't have to take our word for how it handles your code — you can read it, audit it, and even self-host it. Trust earned by inspection beats trust demanded by a marketing page.
View source on konnosAccess control
You decide who gets in, and how far
Strong, layered access control across people, machines, and automation — so the right person has exactly the right reach, and no more.
- Two-factor authentication (2FA) on your account
- SSH and GPG keys for signed, verified access
- Scoped access tokens you can rotate and revoke at will
- Roles & permissions across orgs, teams, and repositories
Encryption in transit
Protected on every connection
All traffic to konnos is encrypted in transit. Browse and clone over HTTPS, or push and pull over SSH — either way, what travels between you and your repositories is sealed against anyone listening on the wire.
Responsible disclosure
Found a vulnerability? Tell us first.
We want to hear from you. Please report it privately through our contact form so we can fix it before any details are made public — and we'll keep you in the loop the whole way.