Trust & Security

What happens to your data,
stated plainly.

PatchVex is not yet SOC 2 or ISO 27001 certified. Where a capability is roadmap, it's labeled roadmap — not a badge implying something that isn't true yet.

Data handling

Per-product data flow

Web Scanner

Fetches only publicly accessible URLs (private and internal network ranges are always blocked — see below). The target URL and findings are stored so the report page keeps working on reload and can be shared by link. There is currently no automatic deletion — treat a scan link as something you can share, not something private.

VulnPilot

Processes findings entirely on your machine. No scan data, findings, or credentials are transmitted to PatchVex or any third party. Fully auditable — MIT licensed.

Deployment

The Web Scanner is a single cloud-hosted service at patchvex.com. There is no separate on-premises or VPC deployment offering today.

Compliance

Current status

StandardStatusDetail
SOC 2 Type IIRoadmapNot yet certified. SOC 2 readiness is part of our long-term roadmap.
ISO 27001RoadmapNot yet certified. Security controls are being designed with future ISO 27001 compliance in mind.

Questions

Security disclosures and data requests

For security disclosures, data processing agreements, or subprocessor questions, contact us directly.