Security & privacy

Your code, your rules

Privacy isn't a feature we bolt on — it's the reason konnos exists. Private by default, open to audit, no lock-in, and locked down on every connection.

No lock-in

Plain Git — yours to export, any time

It's plain Git underneath. Every repository, every byte of LFS, every backup is yours to clone, push, and export whenever you want. Staying with konnos is a choice, never a trap — your code is never held hostage.

Private by default

Closed until you decide otherwise

Every repository starts private. Nothing is visible to anyone — not other users, not search engines, not us beyond what's needed to run the service — until you explicitly choose to open it. Exposure is always a deliberate act, never an accident.

Transparency

Open-source and auditable

konnos is built in the open. You don't have to take our word for how it handles your code — you can read it, audit it, and even self-host it. Trust earned by inspection beats trust demanded by a marketing page.

View source on konnos

Access control

You decide who gets in, and how far

Strong, layered access control across people, machines, and automation — so the right person has exactly the right reach, and no more.

  • Two-factor authentication (2FA) on your account
  • SSH and GPG keys for signed, verified access
  • Scoped access tokens you can rotate and revoke at will
  • Roles & permissions across orgs, teams, and repositories

Encryption in transit

Protected on every connection

All traffic to konnos is encrypted in transit. Browse and clone over HTTPS, or push and pull over SSH — either way, what travels between you and your repositories is sealed against anyone listening on the wire.

Responsible disclosure

Found a vulnerability? Tell us first.

We want to hear from you. Please report it privately through our contact form so we can fix it before any details are made public — and we'll keep you in the loop the whole way.