Security & data

Where your plans live,and who can reach them.

Plain answers to the questions a buyer asks before a team signs in. What is here is what runs today; what is not here yet is said so.

Hosting

Cloudflare’s network

Kurdinator runs on Cloudflare Workers. Each workspace is its own Durable Object with its own storage; one company’s data is never in another’s process. Files attached to tasks are stored in Cloudflare R2 when file storage is switched on for the deployment.

In transit

TLS everywhere

Every request is over HTTPS. Cross-site requests to the API are refused; the session cookie is HttpOnly and SameSite.

Passwords

Never stored, never seen

Passwords are hashed with PBKDF2-SHA256 at 600,000 iterations with a salt per account. Sign-in attempts are throttled per network. Google sign-in is available; Microsoft where the deployment enables it.

Access

Decided on the server

Roles, grants and plan limits are enforced in the Worker, never trusted from the browser. Admins run the workspace; employees see the plans they are on and update only their own tasks. Every access change is written to the workspace log.

Your data

Yours to take

A full JSON export of a workspace is available on request, and plans export to CSV from inside the product. Deleting a project removes it and the files it carried. Account and workspace deletion is done on request through the support desk, and confirmed in writing.

The AI

Reads, does not keep

When a blueprint is built from your documents, their text is sent to the AI provider to be read and the result is stored; Kurdinator keeps the file names and sizes, not the files. Where the AI is not connected, the product says so and works by rules.

What is logged

Inside a workspace: who changed what, when — plans published, owners set, statuses moved, approvals decided, members added. That log is readable by the workspace’s admins. Across the service: sign-ins, plan changes and support tickets, readable only by the operator, with no plan content in them.

What is not here yet

  • Two-factor authentication. Not yet. Google sign-in with your organisation’s own 2FA is the strongest option today.
  • SAML single sign-on and directory sync. Enterprise requirements; scoped in the contract.
  • A data-location commitment. Storage follows Cloudflare’s network. A fixed region is an Enterprise conversation, not a checkbox.
  • Third-party audits. No SOC 2 or ISO 27001 report exists for Kurdinator today. We will not imply otherwise.

Reporting a problem

Anything that looks like a security issue: write to the support desk from inside the product, or ask for a walkthrough and mark it security. It is read by the owner, not a queue.

This page describes the product as of September 2026.