Skip to main content
PPennScan
Dashboard
Trust Center

Trust

Last updated 2026-04-22.

PennScan is a security product, so we hold ourselves to the bar we help our customers meet. This page is the single place to find our security posture, the third parties we rely on, and the legal artifacts procurement teams ask for — stated plainly, with nothing overclaimed.

Security overview

Data in transit is TLS 1.2+ with HSTS on every route; data at rest is encrypted by our database and storage provider. Access is scoped per organization, API keys carry read / write / full scopes, and TOTP and WebAuthn are available for account MFA. Security-relevant events are logged and can be shipped to your SIEM. We dogfood the scanner against our own code on every change.

We run a real vulnerability-disclosure program with response commitments and legal safe harbor for good-faith research — the full policy, scope, and reporting path are on /security. To report something sensitive, email security@pennscan.com.

Sub-processors

We publish a versioned register of every third party that processes customer data on our behalf — Vercel (hosting/CDN), Supabase (database, storage, edge functions), Fly.io (scan worker), Anthropic (AI analysis), Stripe (billing), and Resend (transactional email). We use Anthropic Claude for AI — not OpenAI. Self-hosted and air-gapped deployments use none of these; all data stays inside your own infrastructure.

Additions or replacements are announced in advance, with a contractual objection window for DPA-bound customers before any new sub-processor begins processing your data. To subscribe to change notices, email legal@pennscan.com.

Data processing & DPA

A Data Processing Agreement is available on request — email legal@pennscan.com. Our data-handling practices, retention windows, and your export/deletion rights (GDPR/CCPA) are described on /privacy; the rules of the service are on /terms.

Compliance posture

We’ll be straight about where we are. We follow SOC-2-aligned practices — encryption, least-privilege access, audit logging, CI security gates, and a documented incident process — but we are not yet SOC 2 audited, and we hold no ISO 27001, HITRUST, or PCI certification. Card data is handled entirely by Stripe and never touches our systems. If your review needs a control we don’t have yet, we’ll tell you rather than imply otherwise.

Security reviews & questionnaires

Sending a CAIQ, SIG-Lite, or vendor risk assessment? We keep an evidence-backed answer bank and will complete your questionnaire with sources for each answer. Reach us at legal@pennscan.com or via /contact.

Availability & incidents

Live status and our incident history are on /status. Security advisories and material changes are published on /changelog.

This page summarizes our posture in good faith; the signed DPA, order form, or MSA governs where they conflict with this summary.

PennScan — powered by the Pennscan engine. Authorized targets only. Privacy · Terms · Security · Contact · Changelog · Status · 034fa098