VulnQuill logoVulnQuill
Security

Trust & security

Last updated: 29 July 2026

VulnQuill holds your clients' most sensitive material — unpatched vulnerabilities, exploit evidence, internal hostnames. This page describes, plainly and without compliance theater, how that data is protected. Questions or disclosures: mail@anir0y.in.

Tenant isolation

Every workspace is organization-scoped. Authorization is enforced inside every server action — not just at the routing layer — using a shared access-control check (same-org or explicit engagement membership; client-portal users must be members). Admin rights are re-read from the database on sensitive mutations, never trusted from the session token.

Authentication

Application security

Auditability

Two audit layers: a per-organization activity log (who did what, visible to your admins) and an append-only platform audit log for operator actions. Data exports are themselves logged.

Durability & operations

What we don't claim

VulnQuill is an independent product and does not currently hold SOC 2 or ISO 27001 certification. We'd rather tell you exactly what is implemented than sell you a badge. If your procurement needs a security questionnaire answered, email us — we answer them honestly and fast.

Vulnerability disclosure

Found a vulnerability in VulnQuill? Email mail@anir0y.in (see security.txt). Good-faith research against your own workspace is welcome; don't access other tenants' data. Disclosures are credited in the changelog with your permission.