Trust Center

We hold the crown jewels of your security program.
We treat them that way.

Scan Ninja handles vulnerability telemetry, audit evidence, and compliance gaps from your environment. This page is how we proactively answer the questions your Infosec team is going to ask.

SOC 2 Type II

Audit in progress

NIST 800-171 / CMMC 2.0

Aligned controls

AES-256 · TLS 1.3

Encrypted end to end

Texas C-Corp

D-U-N-S 134682197

Capital Factory Portfolio

Austin, TX accelerator

100% US-Based Team

No offshore · Houston, TX

Veteran-Owned

Service-Disabled Veteran-Owned (SDVOSB)

US-Based & Veteran-Owned

Your data never leaves U.S. hands.

Scan Ninja is a veteran-owned company headquartered in Houston, Texas. Our entire team is based in the United States — we have no offshore staff or resources. Every piece of customer security data, audit evidence, and vulnerability telemetry is handled and reviewed only by U.S. citizens.

  • 100% US-based staff. No offshoring, no third-country contractors touching your environment.
  • Reviewed by U.S. citizens. The people who see your data are vetted U.S. citizens on American soil.
  • Veteran-owned. Founded and led by a service-disabled U.S. military veteran — a Service-Disabled Veteran-Owned Small Business (SDVOSB).

How we operate

Compliance Posture

SOC 2 Type II audit in progress. Controls aligned to NIST 800-171 and CMMC 2.0. We use Scan Ninja to maintain our own continuous compliance — proof of concept for every buyer.

AI Data Boundaries

Your vulnerability telemetry is siloed to your tenant. We never use customer data to train shared or public models. AI remediation guidance is grounded strictly in your environment, with human-in-the-loop approvals.

Encryption & Isolation

AES-256 at rest, TLS 1.3 in transit. Logical tenant separation across data, compute, and AI inference. Documented retention and deletion policies.

Access Control

Role-based access with least privilege. Internal support cannot view sensitive customer data without explicit, time-bound, audited consent.

Integration Security

Connections to cloud platforms, identity providers, and other integrations use OAuth 2.0 or scoped API tokens, request read-only / least-privilege access, and credentials are stored in a managed secrets vault.

Incident Response

Defined SLAs for Critical / High / Medium / Low platform vulnerabilities. Customer notification within 24–48 hours of a confirmed security incident, via designated platform admins.

Responsible disclosure

If you believe you've found a security vulnerability in the Scan Ninja platform, please report it via the address in our security.txt. We commit to acknowledge reports within two business days and to keep researchers informed throughout triage and remediation.