Trust & Security

What happens to your data,
stated plainly.

PatchVex is not yet SOC 2 or ISO 27001 certified. Where a capability is roadmap, it's labeled roadmap — not a badge implying something that isn't true yet.

Data handling

Per-product data flow

Web Scanner

Fetches only publicly accessible URLs. Scan results are stored temporarily for report sharing and are not used for any purpose beyond delivering the report.

VulnPilot

Processes findings entirely on your machine. No scan data, findings, or credentials are transmitted to PatchVex or any third party. Fully auditable — MIT licensed.

Deployment options

Cloud-hosted (multi-tenant) available today. On-premises and VPC deployment available for enterprise customers with data residency requirements.

Compliance

Current status

StandardStatusDetail
SOC 2 Type IIRoadmapNot yet certified. SOC 2 readiness is part of our long-term roadmap.
ISO 27001RoadmapNot yet certified. Security controls are being designed with future ISO 27001 compliance in mind.

Questions

Security disclosures and data requests

For security disclosures, data processing agreements, or subprocessor questions, contact us directly.