Trust Center
How we protect what you share with us, in plain language. For the full technical detail behind any section, follow the links to our Security page and legal documents.
The short version
BreachSpider is built by an active ICS and OT vulnerability researcher, and we hold our own platform to the standard we ask of the operators we serve. We collect only what we need, we never touch your control network, and we are honest about what we do and do not have in place today.
We never touch your control network
BreachSpider is passive. We do not connect to, scan, or alter your control systems. We work from the asset information you provide, equipment, vendor, model, version, and operational context, and we do not need or collect credentials, configurations, or control-network access. Your operations are never at risk from us.
How we handle your data
- We collect the minimum. Only the asset details needed to match vulnerabilities to your environment.
- It stays in the United States. Hosted in a US region, and your data does not leave the country.
- It is isolated to you. Every record is separated by organization, and access across organizations is architecturally prevented.
- It is encrypted. In transit and at rest.
- It is used only for you. Your asset data is used to identify your exposure, and for nothing else. Where we improve our methods, we use only fully anonymized, non-attributable observations, never anything that identifies you or your environment.
- You control retention. Data is returned or deleted at your direction.
See our Security page and Data Processing Addendum for the technical detail.
How we use AI
We are specific about this, because you deserve to be.
- Our core work, matching vulnerabilities to your exact equipment and versions and prioritizing them, is deterministic. It is not a language model guessing.
- Where we use automated analysis to enrich findings, it is labeled as automated analysis, not presented as human research.
- Our interactive assistant uses a third-party inference provider under that provider's data-handling terms. Those queries are not retained beyond the session in our systems, and your data is not used to train external models.
Security architecture
Passwordless authentication, hashed session tokens, optional multi-factor authentication, a restricted database role with per-organization row-level security, a locked-down network, and audit logging of privileged actions. Nightly encrypted backups with defined recovery objectives. The full architecture is documented on our Security page.
Responsible disclosure
We practice what we sell. We welcome good-faith vulnerability reports, commit to a remediation window, and will not pursue legal action against researchers operating in good faith and within scope. Report to [email protected], and see our machine-readable policy at /.well-known/security.txt.
Compliance, honestly stated
We tell you where we actually are, not where we wish we were.
- SOC 2 Type II: in progress, targeted for late 2026, with the platform designed against the Trust Services Criteria.
- NERC CIP and IEC 62443: our platform is aligned with and designed to support the patch-management and vulnerability-assessment workflows in these standards. We do not claim certification.
Talk to us
For security questionnaires, compliance documentation, an NDA, or any question this page does not answer, reach us at [email protected].