PatchVex
ProductDevelopersResourcesTrust
Log inRequest early accessStart free scan

Security Testing Authorization

PatchVex is in early development. This document describes how authorization to scan works today, and will be expanded as the product matures. It is part of our Terms and should be read together with our Acceptable Use Policy.

1. You must be authorized to scan every target you submit

By submitting a URL, domain, repository, or any other target to PatchVex, you represent that you own that target, or that you have the explicit permission of its owner, to have it scanned and analyzed. This applies to every kind of target PatchVex can accept, including websites, APIs, domains, IP addresses, source code repositories, and any infrastructure or third-party integration reachable from a target you submit.

PatchVex does not grant you authorization to test anything. Submitting a target to PatchVex is not itself permission to scan it — that permission has to already exist, independently, between you and whoever owns the target. If you would not be allowed to run the equivalent manual check yourself, submitting it to PatchVex does not make it allowed.

2. What this actually covers today

PatchVex currently offers two scan types. Their actual behavior, not a marketing description of it:

  • Surface scans — PatchVex sends standard HTTP requests to the URL you submit and inspects the response: response headers, cookies, TLS certificate, and any scripts served publicly by that page. This is comparable to what a normal browser visit or a handful of automated requests would do — it does not attempt to log in, submit forms, guess credentials, or otherwise interact beyond reading what the server already serves publicly.
  • Deep scans — PatchVex clones the repository you submit into an isolated, ephemeral environment and runs static analysis tools (secret detection, dependency vulnerability checks, static code analysis, and PII pattern detection) against its contents. This does not send network requests to any live, deployed version of your application — it analyzes source code, not a running system.

We do not describe either scan type as "safe" or "non-intrusive" as a blanket claim — a surface scan is still real outbound network traffic against a real system, and you are responsible for confirming your target can handle it, the same way you'd assess any automated tooling before pointing it at a system you care about.

3. Your responsibility

You are responsible for:

  • Confirming you have the right to have each submitted target scanned
  • Understanding what the scan type you choose actually does, per the descriptions above
  • Deciding whether a given target — especially a live production system — is appropriate to scan at all, and when
  • Complying with any laws, contracts, or third-party terms that apply to the target
  • Any consequences of scanning a target you were not, in fact, authorized to scan

PatchVex blocks scans directed at private, internal, and cloud-metadata network addresses as a safety measure protecting PatchVex's own infrastructure. This is not a substitute for your own authorization to scan a target, and its absence for a given address does not mean that address is safe or authorized to scan.

4. Findings are analysis output, not a guarantee

PatchVex's findings are the output of automated analysis. They are not a guarantee that a target is secure, nor a guarantee that every vulnerability present has been found. Automated analysis can produce false positives and can miss real issues (false negatives). Findings require your own review; the severity and prioritization PatchVex shows is informational, not a substitute for your own judgment about your own system. This is consistent with PatchVex's own product principle — evidence over assertion — applied to what we can honestly claim about our own output, not only about what we find.

We do not claim that using PatchVex results in complete security, regulatory compliance, or the absence of vulnerabilities.

5. Safe harbor

PatchVex does not currently operate a vulnerability disclosure or bug-bounty program of its own, and does not offer safe-harbor protection to third parties testing PatchVex's own infrastructure. This document governs your use of PatchVex to scan targets you are authorized to scan — it is not an invitation to test PatchVex itself outside of normal use.

PatchVex

Free web security scanning, plus VulnPilot — open-source vulnerability prioritization.

Open Source · MIT
SOC 2 — roadmap

Platform

  • Architecture
  • Products
  • Web Scanner
  • VulnPilot CLI
  • Early Access

Resources

  • Documentation
  • Blog
  • Security Guides
  • Vulnerability Index
  • CVE Reference
  • Free Tools

Company

  • About
  • Trust & Security
  • Contact
  • GitHub
© 2026 PatchVex. All rights reserved.
PrivacyTermsSecurity