Trust & Security
What happens to your data,
stated plainly.
PatchVex is not yet SOC 2 or ISO 27001 certified. Where a capability is roadmap, it's labeled roadmap — not a badge implying something that isn't true yet.
Data handling
Per-product data flow
Fetches only publicly accessible URLs. Scan results are stored temporarily for report sharing and are not used for any purpose beyond delivering the report.
Processes findings entirely on your machine. No scan data, findings, or credentials are transmitted to PatchVex or any third party. Fully auditable — MIT licensed.
Cloud-hosted (multi-tenant) available today. On-premises and VPC deployment available for enterprise customers with data residency requirements.
Compliance
Current status
| Standard | Status | Detail |
|---|---|---|
| SOC 2 Type II | Roadmap | Not yet certified. SOC 2 readiness is part of our long-term roadmap. |
| ISO 27001 | Roadmap | Not yet certified. Security controls are being designed with future ISO 27001 compliance in mind. |
Questions
Security disclosures and data requests
For security disclosures, data processing agreements, or subprocessor questions, contact us directly.