Security

Last updated: 1 September 2026

Our approach

Security is built into ScanFix at every layer — from input validation through to AI prompt injection guards. We apply the principle of least privilege and defence-in-depth.

Controls in place

Reporting vulnerabilities

If you discover a security vulnerability, please report it responsibly by emailing security@scanfix.dev. We aim to acknowledge reports within 48 hours and will keep you informed as we investigate. Please do not disclose vulnerabilities publicly until we have had a reasonable opportunity to address them.

Penetration testing

We recommend a professional penetration test be conducted before any high-volume or enterprise deployment. Enterprise customers may request our security questionnaire.