Operated by Adore LLC

Security and data handling.

Patchhound reviews only artifacts you are authorized to submit. It is built to surface exploit-chain risk without collecting production secrets or running active tests from the console.

Review boundary

Patchhound reports are evidence-backed engineering artifacts. They are not a guarantee of security, a certified compliance audit, or a hands-on penetration test unless a separate reviewed agreement says so.

Authorization-only

Every project requires ownership or written authorization plus a scoped attestation.

Artifact-first analysis

Patchhound does not run active live tests, port probing, exploit execution, or arbitrary URL scans from this workflow.

No production secrets

Secret-like patterns are rejected before artifacts are stored for analysis.

Data minimization

Submit snippets and descriptions, not customer exports, credentials, private keys, or payment data.

Evidence labels

Reports show deterministic checks, confidence, reproduction reasoning, and fix steps.

No compliance overclaim

Patchhound is not a formal compliance audit or certified pentest by default.