ScanWrench treats security as a product boundary, not a badge. These are implemented controls and published limitations. They are not a claim of independent certification, penetration-test completion, SOC 2 attestation, ISO 27001 certification, or perfect security.
Browser isolation
The public site blocks framing, objects, broad device permissions, cross-origin resource use, and mixed-content requests.
Bounded API gateway
The public API path accepts bounded requests, removes ambient browser credentials, limits redirects, times out upstream calls, and keeps API responses out of search indexes.
Native command firewall
Read-only diagnostics are the default. State-changing functions require an exact supported workflow, fresh confirmation, and applicable vehicle-state checks.
Signed release evidence
Desktop update metadata and eligible diagnostic artifacts use pinned signing identities. A valid signature proves origin and integrity, not physical compatibility.
Signed operating evidence
Operational readiness requires current Ed25519-signed control records bound to the exact control catalog and deployed release. Environment switches alone cannot turn readiness green.
Local data choices
People may use Device Only or Save Nothing without creating a cloud account. Save Nothing is designed to erase the local session instead of quietly retaining it.
Fail-closed coverage
Unknown adapter, vehicle, module, profile, account, purchase, or authorization states do not become supported merely because a request reached the software.
Health-data boundary
Explicit electronic protected health information field names are rejected before product processing. Free text is not represented as medically classified, so users are instructed not to submit health information.
Readiness targets and exact status
- SOC 2: Security, Availability, and Confidentiality readiness target. No CPA examination or SOC 2 report has been completed.
- ISO/IEC 27001:2022 with Amendment 1:2024: ISMS readiness target with a risk register and Statement of Applicability. ScanWrench is not ISO certified.
- OWASP ASVS 5.0.0 Level 2: web and API verification target. Independent requirement-by-requirement verification remains external.
- OWASP MASVS and MASTG: iOS and Android verification target. A physical release-build assessment remains external.
- HIPAA: deny-by-default product boundary, not a compliance claim. Applicability requires a qualified determination of covered-entity or business-associate status. ScanWrench does not accept ePHI and does not claim HIPAA compliance.
The public security readiness endpoint remains unavailable until operational controls have current signed evidence. It also keeps certification, attestation, independent-verification, and HIPAA-compliance claims false.
Report a vulnerability
Use the private ScanWrench security intake. Include the affected surface, reproducible steps, impact, and a safe way to contact you. Do not include passwords, access tokens, full VINs, payment-card data, identity documents, OEM credentials, or live exploit material that could endanger a vehicle.
Our machine-readable disclosure record is available at /.well-known/security.txt.
Safe testing boundaries
- Use accounts, adapters, vehicles, and data you own or are explicitly authorized to test.
- Do not disrupt service, access another person's data, bypass an OEM gateway, or issue unsafe vehicle commands.
- Stop if testing could move a vehicle, start equipment, disable a safeguard, damage an ECU, expose private data, or affect another user.
- Give ScanWrench reasonable time to investigate before public disclosure.
What remains external
Independent penetration testing, a CPA-led SOC 2 examination, accredited ISO certification, independent OWASP verification, HIPAA legal applicability review, production key-custody review, OEM authorization, and physical adapter and vehicle validation require qualified external parties and real evidence. ScanWrench records these separately from code-level readiness and does not represent them as complete until evidence exists.
Review official correspondence and anti-phishing rules or review the privacy policy.
