AutoExplore Security Overview
Last updated: 2026-08-27
This document summarizes AutoExplore's main security, privacy, and continuity practices for prospects, customers, and partners.
Related public documents:
- Privacy Policy: https://www.autoexplore.ai/privacy
- Terms of Service: https://www.autoexplore.ai/tos
- Accessibility Statement: https://www.autoexplore.ai/accessibility
- Subprocessor List: https://www.autoexplore.ai/subprocessors
Production access and customer data access are limited to authorized personnel who need access to operate, support, and improve the service.
1. Our Commitments
The commitments below apply to the AutoExplore service as a whole. They are stated as properties of the service rather than as a dependency on any single cloud provider, so that they continue to hold if we change or add infrastructure providers.
| Commitment | What this means |
|---|---|
| EU/EEA data residency | Customer data is stored and processed in EU/EEA regions, including AI processing. We do not move customer data outside the EU/EEA without a lawful transfer basis and, where required, prior notice to affected customers. |
| Qualified infrastructure providers | We host on established enterprise cloud platforms that maintain recognized independent security certifications (such as ISO/IEC 27001 and SOC 2), offer EU/EEA regions, and provide GDPR-compliant data processing terms including EU Standard Contractual Clauses where relevant. |
| No training on customer data | Customer data and content submitted to the service are not used to train third-party foundation models. AI providers are engaged under enterprise terms that exclude customer content from model training. |
| Encryption in transit and at rest | Customer data is encrypted in transit using current TLS versions and encrypted at rest using industry-standard algorithms and managed key services. |
| Tenant separation | Customer environments and customer data are kept logically separated, and access is scoped per customer. |
| Transparency on change | Our subprocessors and their processing locations are published and maintained, and material changes are announced in advance as described in the Subprocessor List. |
2. Hosting and Infrastructure
- AutoExplore operates its core service on established enterprise cloud platforms that meet the criteria described in Section 1.
- Production workloads run in EU/EEA regions. The specific providers and regions currently in use are named in our Subprocessor List.
- Public-facing services and APIs are protected through managed edge, network, and traffic-filtering controls.
- Infrastructure runs in secured and monitored datacenter environments operated by our cloud providers under their own certified physical and environmental security programs.
- We design the service to remain portable across providers and avoid dependencies that would prevent us from meeting the commitments in Section 1.
3. Security Controls
- HTTPS/TLS is used end-to-end for data in transit.
- Data processed by the service is protected with strong encryption where appropriate.
- Encryption and key management follow generally accepted security practices and use managed key and secret services provided by our cloud platforms.
- Vulnerability assessments and security reviews are part of ongoing security management.
4. Secure Development and Application Security
- Security is considered throughout design, development, testing, and release.
- AutoExplore uses continuous testing, including AutoExplore itself where applicable, to detect defects and regressions.
- Dependencies and libraries are reviewed and updated regularly.
- Known vulnerabilities in application code and dependencies are tracked and addressed based on severity and impact.
5. Privacy and Data Handling
- AutoExplore processes customer configuration data, scan results, report data, and related operational data.
- The service stores screenshots, HTML snapshots, and related report artifacts from the Target Software.
- Data is classified based on sensitivity.
- Customer environments and customer data are kept logically separated.
- Customer data hosting and AI processing take place in EU/EEA regions.
- Data is retained only as long as the intended purpose, customer relationship, or applicable law requires.
- We support applicable GDPR obligations, including access, rectification, deletion, and other relevant data subject rights.
- Responsibility for information security and privacy oversight currently rests with the AutoExplore CEO.
6. AI Processing
- AutoExplore uses large language models and in-house classification models to analyze and prioritize findings produced by the service.
- AI model services may process scan outputs, page-derived text, screenshots, HTML snapshots, issue descriptions, prompts, and responses needed to generate results.
- AI processing is performed in EU/EEA regions. We select model endpoints and deployment regions specifically to keep processing within the EU/EEA, and we do not route customer content through endpoints that would place processing outside it.
- Customer data and content are not used to train third-party foundation models. AI providers are engaged under enterprise terms that exclude customer content from model training and from human review for product-improvement purposes.
- Model providers and model versions change as the field develops. We select AI providers using the criteria in Section 1, name the providers currently in use in our Subprocessor List, and announce changes in advance as described there.
7. Access Management
- Access is granted based on role and business need.
- Least privilege is applied.
- Access is reviewed, changed, and removed when no longer needed.
- All AutoExplore user accounts require multi-factor authentication.
- User logins are logged and monitored to detect malicious or suspicious access attempts.
- Public API access is protected through layered controls, including edge validation and API key-based access controls.
8. Monitoring, Logging, and Incident Handling
- AutoExplore uses cloud-native monitoring and diagnostics tooling for real-time visibility into service health and security-relevant events.
- Login activity and other critical security-relevant actions are monitored in real time.
- Logs are used for security, service reliability, troubleshooting, and misuse detection.
- Log access is limited to authorized personnel with a work-related need.
- Log access is controlled and supervised as part of our security practices.
- Logs are retained for a defined period based on security, operational, troubleshooting, and legal requirements.
- Logs are protected against unauthorized access and unauthorized modification.
- Logs are used only for predefined security, operational, and compliance purposes.
- Logging and telemetry are configured to reduce unnecessary exposure of secrets and sensitive parameters where applicable.
- Incidents are handled based on severity and impact, with containment, recovery, root-cause analysis, and follow-up actions.
- Customers are informed of relevant security incidents where required by contract, law, or the nature of the incident.
9. Availability and Recovery
- Critical data is backed up using managed, automated backup and recovery tooling. Backups are held in EU/EEA regions.
- Recovery capabilities are maintained and tested.
- Infrastructure is defined as version-controlled infrastructure-as-code, which together with data backups supports rebuilding the environment.
- Third-party dependencies are considered in continuity planning.
10. Suppliers and Transparency
- Selected third-party providers support service delivery and business operations.
- Providers are assessed before use against the criteria in Section 1, and relevant security, confidentiality, and data protection terms are applied where needed.
- The current public Subprocessor List is maintained, and changes are announced in advance as described there.
- We share relevant security and supplier information with prospects and customers and communicate relevant service and security changes where applicable.
11. Governance
- The CEO is responsible for overall information security, privacy oversight, supplier oversight, risk decisions, and incident escalation.
- Personnel are required to follow approved security practices and report incidents or weaknesses without delay.
- This overview and supporting practices are reviewed at least annually and when significant changes occur.
Contact
For security or privacy questions, contact info@autoexplore.ai