Trust and compliance.
If you are reviewing us, start here. This is how we secure the platform and what we do with your data.
Last updated 28 June 2026.
Segmented execution
Every dynamic scan runs in an ephemeral, network-segmented micro-VM that is destroyed after the run, so untrusted code never touches the main platform or your environment.
Data handling
We process artifacts and findings, not personal browsing. Data is encrypted in transit and at rest. Ask us what retention and regional storage we can commit to for your account before you sign anything.
Access controls
Multi-tenant isolation, role-based access control, full audit logging, and single sign-on with SCIM provisioning keep access scoped and accountable.
Secret handling
Discovered secrets are encrypted at rest and shown in full to the analyst who owns the scan, because a masked value cannot be searched for or rotated. They are never sold or shared. When AI code analysis is enabled, the source files selected for review - which are where a leaked credential sits - are sent to our model provider for that scan; turn AI analysis off and no source leaves the platform.
Responsible disclosure
We welcome reports from security researchers and publish our policy, contact, and expiry per RFC 9116 at /.well-known/security.txt.
Compliance posture
Extuno is built to GDPR-aligned data-handling practices. Enterprise customers can request a current security overview and data processing terms.
Questions? Use the contact page.