You're inviting us to look at your systems — so you deserve to know exactly how we handle that access, where your data lives, and what we do (and never do) with it. No vague assurances. Here's the whole picture.
Our server agent is the deepest access we ask for — so it's the most locked-down thing we build. Four hard guarantees:
It observes — checks patches, config, logs, running processes. It does not change your system. The only actions it can ever take are a short list of reversible containment steps, and only when a human on your side approves each one.
The agent opens no ports and accepts no inbound connections. It reaches out to us — never the other way around — so it never widens your attack surface.
The install script is served in the open and its source is published. You (or your engineers) can read exactly what will run on your machine before you run it — no black box.
A scan reads what it needs, reports the findings, and moves on. We don't keep copies of your source, your files, or your logs sitting on disk after the work is done.
Straight answers on hosting, encryption, and retention — the questions any security-conscious buyer asks first.
| Hosting region | UK/EU — our application and database run in AWS eu-west-1 (Ireland). Your data does not leave the region. |
| Encryption in transit | Everything is served over TLS. The agent's connection back to us is encrypted end to end. |
| Encryption at rest | Our managed database (AWS RDS) encrypts stored data at rest. |
| Scan artefacts | Findings are stored against your account so you can see your history. Raw material a scan reads (page source, file contents, logs) is not retained after the scan completes. |
| Authentication | Passwordless — we email you a one-time 6-digit code. We never store a password to your account because there isn't one. |
| Payments | Handled entirely by Stripe. We never see or store your card details. |
| Sub-processors | AWS (hosting), Stripe (payments), Cloudflare (DNS/edge), Resend (transactional email). That's the full list. |
Active and pentest work can touch your systems, so consent and scope are built into the flow, not an afterthought.
Active checks (open ports, deeper probing) only run once you've verified ownership of a domain with a DNS record. This protects you — and everyone else — from being scanned without permission.
Every human pentest starts with a written scope and an explicit authorisation that you own or may permit testing of the targets. We only touch what's on the list.
We're a security company — we take our own security seriously and we welcome reports. If you believe you've found a vulnerability in our systems, tell us privately first and give us a reasonable window to fix it before any public disclosure. We'll respond, keep you updated, and credit you if you'd like.
Email support@solvbeat.co.uk with "Security" in the subject.