Trust
Security overview
We design Scanpubs with defense-in-depth in mind. This page summarizes our posture at a high level and will evolve as the product matures.
Last updated:
Transport and sessions
We use modern TLS for data in transit. Authentication sessions use industry-standard cookies and token practices appropriate to our stack.
Access control
Dashboard data is scoped to your account. Administrative access is limited to trained operators and audited where required for support or reliability work.
Infrastructure
Production workloads run on reputable cloud providers with hardened configurations, automated patching where applicable, and segregated environments for testing versus production.
Reporting issues
If you believe you have found a vulnerability, reach us via the contact form with reproduction steps and the subject line “Security report.” Please allow reasonable time before public disclosure.
