Trust & Security
Security at BreachVex
We run offensive security for a living. We hold ourselves to the same standards we ask of our customers.
Responsible Disclosure
If you discover a security issue in BreachVex or our infrastructure, we want to hear from you.
- Scope: the breachvex.com domain, our public APIs, the BreachVex worker, and any first-party subdomain.
- Safe harbor: we will not pursue legal action against researchers acting in good faith — no DoS, no data exfiltration beyond what is needed to demonstrate impact, no social engineering of staff.
- Reporting: email security@breachvex.com with a clear writeup and reproduction steps.
- Encrypted reports: request our preferred encrypted channel in your initial email; we will respond out-of-band.
- SLA: acknowledgement within 48 hours. Triage and remediation target of 30 days for high/critical issues.
- Coordinated disclosure: we agree on a public disclosure date with the reporter on a case-by-case basis.
Out of scope
- Denial-of-service or DDoS attacks against our infrastructure.
- Social engineering of staff, contractors, or customers.
- Vulnerabilities in third-party services we depend on (please report to the upstream vendor).
Data Handling
- Workers are ephemeral: each scan runs real, industry-standard offensive tooling in a fresh, single-use isolated container that is destroyed when the scan ends.
- Credentials encryption: AES-256-GCM on the credentials you supply for authenticated scans, under a server-side key you never hold. TLS 1.3 in transit.
- EU-hosted data: customer scan data is stored and processed in the EU. Some website-layer processors operate outside the EEA under Standard Contractual Clauses — full list in our Privacy Policy.
- Evidence capture: proving an access-control flaw requires showing the data it exposes, so a finding can carry a response excerpt capped at 3,000 characters. Excerpts exist to demonstrate impact and are never used for anything else.
- Worker log retention: 90 days, kept for debugging. Scan reports follow your retention settings.
- GDPR: privacy-by-design from day one. DPA available on request.
Infrastructure
Our production architecture:
- Sandboxed execution: workers run inside isolated containers with restricted capabilities and no host filesystem access.
- Network isolation: each scan runs in its own network namespace; no cross-tenant traffic.
- No persistent customer data on workers — state lives in our encrypted database, not on the fleet.
Authorization & Scope
Customers must sign an authorization statement before any scan starts. We refuse to scan assets without explicit, written scope. Running a pentest without authorization is illegal in most jurisdictions — we won't be a party to it.
Hall of Fame
Researchers who reported valid issues will be credited here — with their consent. No reports received yet.
Machine-readable policy: /.well-known/security.txt. Questions? Contact us.
Last updated: May 15, 2026 · Policy version 1.0