Security & trust

Last updated 8 July 2026

BreachLens is a security product, so we hold ourselves to the standard we ask of our customers. The most important fact: BreachLens is self-hosted by design — your source code, scan results, and findings stay on infrastructure you control. We (the company) never receive them.

Architecture: your data never leaves your infrastructure

BreachLens runs as a single stack on your own cluster. Scans execute on your infrastructure and findings are stored in your database. There is no required call-home, and no copy of your code or results is sent to us.

Air-gapped & offline

BreachLens can run fully air-gapped, with zero outbound dependencies — including the AI, via local inference. This is a first-class deployment mode, built for regulated and classified environments, not an afterthought.

Access & authentication

Compliance

We're building toward SOC 2, and a formal audit is planned. BreachLens is built for air-gapped and regulated buyers; deployment on infrastructure you already accredit keeps your existing controls and boundary intact.

Responsible disclosure

If you believe you've found a security issue in BreachLens or this website, we want to hear from you. Email security@breachlens.app. Our machine-readable policy lives at /.well-known/security.txt. We welcome good-faith research and won't pursue action against researchers who follow this policy.

← Back to home