Skip to main content

ExecBound trust center

This is where ExecBound publishes what it claims about its own security, what it does not claim, and the evidence for each claim. Every page here is published from the same repository as the product, and the tests it names run on every change. The product documentation is at docs.execbound.ai.

Where things stand​

ExecBound has no SOC 2 report, no ISO 27001 certification and no third-party penetration test. What it offers instead is the evidence below: the threat model it is built against, the required behavior, and the test that shows each behavior holds. Known limits are written down beside the claims, starting with the threat model's residual risks.

The hosted service runs on Render for application and static hosting and on Supabase for PostgreSQL. The privacy notice says what it stores.

To report a vulnerability, follow the disclosure policy; the contact is also in security.txt.

Security model​

What ExecBound defends, against whom, and where each credential is kept.

Evidence​

Every required behavior, and the test that shows it holds.