Trust Center

Last updated: August 29, 2026 - Contact: [email protected]

How we protect what you share with us, in plain language. For the full technical detail behind any section, follow the links to our Security page and legal documents.

The short version

BreachSpider is built by an active ICS and OT vulnerability researcher, and we hold our own platform to the standard we ask of the operators we serve. We collect only what we need, we never touch your control network, and we are honest about what we do and do not have in place today.

We never touch your control network

BreachSpider is passive. We do not connect to, scan, or alter your control systems. We work from the asset information you provide, equipment, vendor, model, version, and operational context, and we do not need or collect credentials, configurations, or control-network access. Your operations are never at risk from us.

How we handle your data

See our Security page and Data Processing Addendum for the technical detail.

How we use AI

We are specific about this, because you deserve to be.

Security architecture

Passwordless authentication, hashed session tokens, optional multi-factor authentication, a restricted database role with per-organization row-level security, a locked-down network, and audit logging of privileged actions. Nightly encrypted backups with defined recovery objectives. The full architecture is documented on our Security page.

Responsible disclosure

We practice what we sell. We welcome good-faith vulnerability reports, commit to a remediation window, and will not pursue legal action against researchers operating in good faith and within scope. Report to [email protected], and see our machine-readable policy at /.well-known/security.txt.

Compliance, honestly stated

We tell you where we actually are, not where we wish we were.

Talk to us

For security questionnaires, compliance documentation, an NDA, or any question this page does not answer, reach us at [email protected].