Security

How pentes.io protects your data and stays in scope

Last updated: 2026-06-13 · Contact: security@pentes.io

pentes.io is a security product. The credibility of the report you generate depends on the rigour of the platform that produced it. This page describes the controls we run, the ones that are architectural rather than policy, and the ones we're still maturing.

The architectural rules

These are not "policies we follow" — they are constraints the system enforces. Removing them would require rewriting the worker.

Data protection

Application security

Infrastructure and egress

Operational practices

What we don't yet have

Honest disclosure of the gaps we're closing:

Reporting an issue

If you've found a security vulnerability in our service, the disclosure path is at /responsible-disclosure/. The short version: security@pentes.io, 90-day coordinated disclosure window, we acknowledge within 72 hours.