Trust center

How Exploit Hound handles your data.

A security product asks you to trust it with an unusually complete picture of your network. This page states what the platform does, what it deliberately refuses to do, and what it does not yet have. It claims no certifications, because we hold none.

We do not claim compliance certifications

Exploit Hound is not SOC 2 attested, ISO 27001 certified, PCI validated, HIPAA certified or FedRAMP authorized. Any vendor page implying otherwise about us is wrong. The platform can help you identify technical conditions relevant to several of those frameworks, which is a different claim and the only one we make.

Tenant isolation

Separation is enforced in queries, not by convention

For an MSP, tenants are separate customers. Isolation is applied where data is read rather than left to each screen to remember.

One chokepoint for the graph

Writing a relationship between two entities in different tenants raises an error rather than succeeding quietly. The exposure graph cannot be made to span customers even by a caller that tries.

Same answer for absent and forbidden

A record belonging to another tenant returns the same not-found response as one that does not exist, so responses cannot be used to enumerate what other customers hold.

Secrets

Credentials you give us

At rest

Scanner and directory credentials are encrypted before storage. They are never returned by the API after saving — the interface reports only whether a secret is set — and never written to logs, reports, exports or AI prompts.

In transit

The console and API are served over TLS. Agents authenticate with their own credentials, separate from user accounts, and can be suspended or deleted independently.

Authorized use

What the platform will not do

Assessment capability is bounded deliberately. These are properties of the code, not policies we ask operators to follow.

Scope is explicit

Assets are assessed only when marked authorized, with the authorization recorded. Verify Fix cannot be pointed at a target of your choosing: the target is derived from the finding’s own asset record.

Verification is read-only

A TCP connect, a TLS handshake inspection, a header or banner read. Addresses are resolved and vetted before connection, so a hostname cannot be used to reach internal or reserved ranges.

Directory reads only

Active Directory assessment opens its connection read-only and requests a fixed attribute allowlist that excludes every credential-bearing attribute. It does not crack, spray, read password hashes, or write to a directory.

No arbitrary execution

There is no unrestricted remote command execution and no exploit-execution capability. The AI analyst cannot trigger scanning or any state change.

AI handling

The analyst is optional and grounded

It answers only from the requesting tenant’s own records. Every finding, asset and path it cites is checked against the evidence it was given; anything else is flagged rather than presented as fact, and with no supporting data it says so instead of producing something plausible. Use is recorded, and it can be disabled entirely.

Access

Accounts and audit

Roles

Four levels, from read-only through tenant administrator, with cross-tenant access held separately.

Two-factor

Available on user accounts.

Audit log

Authentication, configuration and remediation state changes are recorded with the acting user.

Vulnerability disclosure

Tell us and we will fix it

If you find a security issue in Exploit Hound, report it through the contact route for your deployment. We will confirm receipt, tell you what we found, and tell you when it is fixed. We will not threaten you for reporting in good faith.

We ask that you test only against your own deployment or data, avoid actions that would degrade service for others, and give us a reasonable window before publishing.

Not yet in place

What this page does not claim

A trust page that lists only strengths is not informative. These are real gaps.

  • No third-party audit

    No SOC 2, ISO 27001 or penetration test report is available, because none has been completed.

  • Backup and retention are deployment-specific

    Exploit Hound can be self-hosted. Backup, retention and recovery depend on how your instance is operated, and we do not make claims about deployments we do not run.

  • No public status page

    Availability is reported per deployment rather than centrally.

Start with what's actually exposed.

Point Exploit Hound at the assets you are authorized to assess and see the connected picture — not another list.

v2.4.1 Exploit Hound 2.4.1 · Continuous Threat Exposure Management