Trust & Security
What happens to your data,
stated plainly.
PatchVex is not yet SOC 2 or ISO 27001 certified. Where a capability is roadmap, it's labeled roadmap — not a badge implying something that isn't true yet.
Data handling
Per-product data flow
Fetches only publicly accessible URLs (private and internal network ranges are always blocked — see below). The target URL and findings are stored so the report page keeps working on reload and can be shared by link. There is currently no automatic deletion — treat a scan link as something you can share, not something private.
Processes findings entirely on your machine. No scan data, findings, or credentials are transmitted to PatchVex or any third party. Fully auditable — MIT licensed.
The Web Scanner is a single cloud-hosted service at patchvex.com. There is no separate on-premises or VPC deployment offering today.
Compliance
Current status
| Standard | Status | Detail |
|---|---|---|
| SOC 2 Type II | Roadmap | Not yet certified. SOC 2 readiness is part of our long-term roadmap. |
| ISO 27001 | Roadmap | Not yet certified. Security controls are being designed with future ISO 27001 compliance in mind. |
Questions
Security disclosures and data requests
For security disclosures, data processing agreements, or subprocessor questions, contact us directly.