Trust Center

What we will never do.

We are an offensive tool pointed at your own systems. That only works if the boundaries are explicit — so here they are, with the limits we will not paper over.

Hold write access to your cloud
We detect and sign. A function you own and deploy holds the credentials and makes the change — so every modification lands in your audit trail, under your role.
Move your data
Content sampling is bounded and stays in your account. Where a disk needs deeper inspection, the worker runs inside your account and transmits findings only — never a value, never a row.
Merge our own code into your repo
Every auto-fix lands as a draft pull request and stops there. A machine-written security fix must be read by a person before it ships.
Claim more than we proved
Findings are labelled by how we know them: observed, reported by another tool, or proven by exploitation. Compliance mappings are evidence toward a control, never a pass.
Train on your code
Source is processed in a throwaway sandbox and is never used to train any model. On Enterprise, on-prem / BYO-key means the model runs on your key inside your environment and your code never reaches us at all.
Block, kill or quarantine in production
The optional eBPF runtime sensor is detection only, off unless you turn it on, and never enforces. Real-time endpoint prevention (isolate a host, kill a process, quarantine a file) is a connected-partner engine, behind our AI rollout-safety gate — the integration is live and activates per workspace once a partner is connected. Admission control and cloud guardrails remain on the roadmap.
Access model

Agentless by default.

Connecting a cloud installs nothing on your servers, and credentials are verified with a real call before they are stored. Public targets require verified domain ownership before we test them. Removing a member revokes their live tokens immediately; deactivating a user in your IdP through SCIM does the same.

Cloud accessagentless
Runtime sensorOptional eBPF, off by default, detection only
Source handlingThrowaway sandbox, never used for training
IdentitySSO (OIDC) and SCIM 2.0 on Enterprise; owner, admin, member, viewer
Stored credentialsSSO client secrets, GitHub and SCIM tokens, network-test credentials, Slack webhooks and signing keys are encrypted at rest (AES-256-GCM); the key is held in the service environment, apart from the data files
AuditWho triggered which scans, and who viewed or exported what
SpendA hard per-scan ceiling concludes a runaway scan cleanly
Evidence, not assertions

Findings map to the frameworks your auditor already uses.

SOC 2 · ISO 27001 · ISO 42001 · PCI DSS · HIPAA · NIST AI RMF · NIST CSF 2.0 · EU AI Act · GDPR Articles 25 and 32. Those mappings are stated as evidence toward a control — never as a pass. We are not your auditor, and a vendor that tells you it has certified you has told you something untrue.

Read the report standard See a sample attestation