// TRUST
We pentest our own product
Vex Raptor is offensive security software. We run the same confidence pipeline on ourselves and close findings before they reach customers.
SEC-0 hygiene (2026-Q3)
Removed personal operator defaults, fail-closed API key scopes, SPA path containment, and plan gates without org context.
Confidence pipeline
CONFIRMED requires independent signals plus double-check re-probes. A 3,000+ test anti-FP corpus guards regressions (3,054 passed, Jul 2026).
Supply chain
pip-audit runs in CI on every merge. Dependencies are pinned in requirements.txt.
Self-hosted by design
Your scan data stays in your infrastructure. Domain authorization gates external targets.
Questions? [email protected]