Trust Center

Procurement answers

The questions a vendor-risk review asks, answered in one place. Every answer below is either a stated fact with its source, or a statement that it is answered during a security review. Nothing here is estimated.

Where we do not hold something, this page says so plainly rather than describing it in a way that reads like we do.

Answers

QuestionAnswer
Hosting providerMSP Reboot (mspreboot.com).
How this is established: Stated by the platform operator, 27 August 2026.
Hosting regionHosted in the Surety Data Center facility (suretydc.com).
How this is established: Stated by the platform operator, 27 August 2026.
Data residencyUnited States.
How this is established: Stated by the platform operator, 28 August 2026.
Current subprocessorsMSP Reboot — hosting and infrastructure. Anthropic — processes finding content where the AI security analyst is enabled. Pushover — notification delivery. Vulnerability and threat-intelligence sources are read from, not sent to, and process no customer data.
How this is established: Confirmed by the platform operator, 28 August 2026, against the outbound services configured on this deployment.
Encryption in transitHTTPS only. TLS 1.2 and TLS 1.3 are accepted; TLS 1.0 and TLS 1.1 are refused.
How this is established: Verified by TLS handshake against the published endpoint, 27 August 2026.
Stored credential encryptionIntegration credentials are encrypted before storage using Fernet (AES-128-CBC with HMAC-SHA256 authentication), with the key derived by PBKDF2-HMAC-SHA256 at 480,000 iterations.
How this is established: apps/api/app/services/encryption.py
Password hashingbcrypt, through passlib, with automatic rehashing on scheme change.
How this is established: apps/api/app/services/auth.py
Backup frequencyDaily, replicated to a second data centre.
How this is established: Stated by the platform operator, 27 August 2026.
Backup encryptionBackups are encrypted.
How this is established: Stated by the platform operator, 27 August 2026.
Last successful recovery testNone performed. Backups exist; a tested recovery has not been carried out, and no recovery time is claimed on the strength of untested backups.
How this is established: docs/SECURITY_POSTURE.md, disaster recovery test: not performed.
RPO and RTOProvided during a security review.
Retention controlsScan and report retention is configurable per tenant, enforced by a scheduled cleanup that acts on the setting rather than leaving it declarative.
How this is established: Published on the Trust Center; enforced by the retention cleanup task.
Tenant deletionDeleting a tenant removes its assets, findings, exposure graph and remediation history by cascade.
How this is established: Database cascade on the tenant relationship.
Tenant deletion timingImmediate. Deletion removes the tenant's records when it is carried out, rather than after a retention window.
How this is established: Stated by the platform operator, 28 August 2026.
Incident reporting contactReported through the contact route published in /.well-known/security.txt, which names only the route shown to work.
How this is established: Generated into the site at build time.
Responsible disclosurePublished policy at /security/#disclosure, with a machine-readable /.well-known/security.txt.
How this is established: Published on the Trust Center.
Data processing agreementNo data processing agreement is available yet. If your procurement process requires one, say so during the security review and it will be answered directly rather than deferred.
How this is established: Stated by the platform operator, 28 August 2026.
Vendor questionnaire processSend the questionnaire through the contact form marked as a security review. It is answered directly, including by a call with an engineer where a document is not what your process needs.
How this is established: Published on the Trust Center at /security/#review.
Independent assuranceNone. There is no SOC 2 report, no ISO 27001 certificate and no independent penetration test. Security testing is carried out by our own engineers and is described as such.
How this is established: docs/SECURITY_POSTURE.md, which tracks each of these as not commissioned.

Reviewed 2026-08-28. Answers are current as of that date; anything that has moved since is answered as it stands during a review.

Send us the questionnaire

Anything this page does not cover is answered directly, including standard vendor-risk questionnaires.

Start a security review Trust Center Report a vulnerability

v2.59.0 Exploit Hound 2.59.0 · Continuous Threat Exposure Management