Security & trust
Last updated 8 July 2026
BreachLens is a security product, so we hold ourselves to the standard we ask of our customers. The most important fact: BreachLens is self-hosted by design — your source code, scan results, and findings stay on infrastructure you control. We (the company) never receive them.
Architecture: your data never leaves your infrastructure
BreachLens runs as a single stack on your own cluster. Scans execute on your infrastructure and findings are stored in your database. There is no required call-home, and no copy of your code or results is sent to us.
Air-gapped & offline
BreachLens can run fully air-gapped, with zero outbound dependencies — including the AI, via local inference. This is a first-class deployment mode, built for regulated and classified environments, not an afterthought.
Access & authentication
- Single sign-on via OIDC (Microsoft Entra, Okta, Auth0, Keycloak, Google Workspace).
- Passkey / WebAuthn and TOTP multi-factor authentication.
- Role-based access control with a five-role hierarchy.
- Audit logging on sensitive actions.
Compliance
We're building toward SOC 2, and a formal audit is planned. BreachLens is built for air-gapped and regulated buyers; deployment on infrastructure you already accredit keeps your existing controls and boundary intact.
Responsible disclosure
If you believe you've found a security issue in BreachLens or this website, we want to hear from you. Email security@breachlens.app. Our machine-readable policy lives at /.well-known/security.txt. We welcome good-faith research and won't pursue action against researchers who follow this policy.
← Back to home