Security at Vulnetix

Everything we build is designed for security first. Vulnetix runs entirely on Cloudflare's global edge with layered safeguards and independent assurance.

Security at a Glance

Cloudflare Platform Assurances

Our platform is Cloudflare-native end to end:

Cloudflare holds independently verified ISO 27001/27701, SOC 2, PCI DSS, and related certifications. See Cloudflare Trust Hub.

GitHub Platform Integration

ISO 27001:2022 External Audit

We have engaged Vanta + Digitech Group to prepare and perform an independent ISO 27001:2022 certification audit. As a startup within our first year, we are establishing an ISMS and running internal audits prior to the external Stage 1 and Stage 2 audits.

Audit scope: risk assessment, control implementation, monitoring, incident response, vendor management, and secure development lifecycle.

Vulnerability Disclosure Policy

We welcome good-faith security research. Email security@vulnetix.com encrypted with our PGP key.

In Scope

Out of Scope

Safe Harbor

Disclosure & Timelines

security.txt

Always available at /.well-known/security.txt

Contact: mailto:security@vulnetix.com
Expires: 2050-01-01T00:00:00.000Z
Preferred-Languages: en
Encryption: https://www.vulnetix.com/pgp-key.txt

PGP public key: /pgp-key.txt

Report a vulnerability: security@vulnetix.com