Operated by Adore LLC
Security and data handling.
Patchhound reviews only artifacts you are authorized to submit. It is built to surface exploit-chain risk without collecting production secrets or running active tests from the console.
Patchhound reports are evidence-backed engineering artifacts. They are not a guarantee of security, a certified compliance audit, or a hands-on penetration test unless a separate reviewed agreement says so.
Authorization-only
Every project requires ownership or written authorization plus a scoped attestation.
Artifact-first analysis
Patchhound does not run active live tests, port probing, exploit execution, or arbitrary URL scans from this workflow.
No production secrets
Secret-like patterns are rejected before artifacts are stored for analysis.
Data minimization
Submit snippets and descriptions, not customer exports, credentials, private keys, or payment data.
Evidence labels
Reports show deterministic checks, confidence, reproduction reasoning, and fix steps.
No compliance overclaim
Patchhound is not a formal compliance audit or certified pentest by default.