Trust center
How Exploit Hound handles your data.
A security product asks you to trust it with an unusually complete picture of your network. This page states what the platform does, what it deliberately refuses to do, and what it does not yet have. It claims no certifications, because we hold none.
We do not claim compliance certifications
Exploit Hound is not SOC 2 attested, ISO 27001 certified, PCI validated, HIPAA certified or FedRAMP authorized. Any vendor page implying otherwise about us is wrong. The platform can help you identify technical conditions relevant to several of those frameworks, which is a different claim and the only one we make.
Tenant isolation
Separation is enforced in queries, not by convention
For an MSP, tenants are separate customers. Isolation is applied where data is read rather than left to each screen to remember.
One chokepoint for the graph
Writing a relationship between two entities in different tenants raises an error rather than succeeding quietly. The exposure graph cannot be made to span customers even by a caller that tries.
Same answer for absent and forbidden
A record belonging to another tenant returns the same not-found response as one that does not exist, so responses cannot be used to enumerate what other customers hold.
Secrets
Credentials you give us
At rest
Scanner and directory credentials are encrypted before storage. They are never returned by the API after saving — the interface reports only whether a secret is set — and never written to logs, reports, exports or AI prompts.
In transit
The console and API are served over TLS. Agents authenticate with their own credentials, separate from user accounts, and can be suspended or deleted independently.
Authorized use
What the platform will not do
Assessment capability is bounded deliberately. These are properties of the code, not policies we ask operators to follow.
Scope is explicit
Assets are assessed only when marked authorized, with the authorization recorded. Verify Fix cannot be pointed at a target of your choosing: the target is derived from the finding’s own asset record.
Verification is read-only
A TCP connect, a TLS handshake inspection, a header or banner read. Addresses are resolved and vetted before connection, so a hostname cannot be used to reach internal or reserved ranges.
Directory reads only
Active Directory assessment opens its connection read-only and requests a fixed attribute allowlist that excludes every credential-bearing attribute. It does not crack, spray, read password hashes, or write to a directory.
No arbitrary execution
There is no unrestricted remote command execution and no exploit-execution capability. The AI analyst cannot trigger scanning or any state change.
AI handling
The analyst is optional and grounded
It answers only from the requesting tenant’s own records. Every finding, asset and path it cites is checked against the evidence it was given; anything else is flagged rather than presented as fact, and with no supporting data it says so instead of producing something plausible. Use is recorded, and it can be disabled entirely.
Access
Accounts and audit
Roles
Four levels, from read-only through tenant administrator, with cross-tenant access held separately.
Two-factor
Available on user accounts.
Audit log
Authentication, configuration and remediation state changes are recorded with the acting user.
Vulnerability disclosure
Tell us and we will fix it
If you find a security issue in Exploit Hound, report it through the contact route for your deployment. We will confirm receipt, tell you what we found, and tell you when it is fixed. We will not threaten you for reporting in good faith.
We ask that you test only against your own deployment or data, avoid actions that would degrade service for others, and give us a reasonable window before publishing.
Not yet in place
What this page does not claim
A trust page that lists only strengths is not informative. These are real gaps.
- —No third-party audit
No SOC 2, ISO 27001 or penetration test report is available, because none has been completed.
- —Backup and retention are deployment-specific
Exploit Hound can be self-hosted. Backup, retention and recovery depend on how your instance is operated, and we do not make claims about deployments we do not run.
- —No public status page
Availability is reported per deployment rather than centrally.
Start with what's actually exposed.
Point Exploit Hound at the assets you are authorized to assess and see the connected picture — not another list.