VulnQuill holds your clients' most sensitive material — unpatched vulnerabilities, exploit evidence, internal hostnames. This page describes, plainly and without compliance theater, how that data is protected. Questions or disclosures: mail@anir0y.in.
Every workspace is organization-scoped. Authorization is enforced inside every server action — not just at the routing layer — using a shared access-control check (same-org or explicit engagement membership; client-portal users must be members). Admin rights are re-read from the database on sensitive mutations, never trusted from the session token.
Two audit layers: a per-organization activity log (who did what, visible to your admins) and an append-only platform audit log for operator actions. Data exports are themselves logged.
VulnQuill is an independent product and does not currently hold SOC 2 or ISO 27001 certification. We'd rather tell you exactly what is implemented than sell you a badge. If your procurement needs a security questionnaire answered, email us — we answer them honestly and fast.
Found a vulnerability in VulnQuill? Email mail@anir0y.in (see security.txt). Good-faith research against your own workspace is welcome; don't access other tenants' data. Disclosures are credited in the changelog with your permission.