ScanWrench — Connect. Diagnose. Drive.
Contact
← Back to ScanWrench

Security center

Effective July 20, 2026

ScanWrench treats security as a product boundary, not a badge. These are implemented controls and published limitations. They are not a claim of independent certification, penetration-test completion, SOC 2 attestation, ISO 27001 certification, or perfect security.

Browser isolation

The public site blocks framing, objects, broad device permissions, cross-origin resource use, and mixed-content requests.

Bounded API gateway

The public API path accepts bounded requests, removes ambient browser credentials, limits redirects, times out upstream calls, and keeps API responses out of search indexes.

Native command firewall

Read-only diagnostics are the default. State-changing functions require an exact supported workflow, fresh confirmation, and applicable vehicle-state checks.

Signed release evidence

Desktop update metadata and eligible diagnostic artifacts use pinned signing identities. A valid signature proves origin and integrity, not physical compatibility.

Local data choices

People may use Device Only or Save Nothing without creating a cloud account. Save Nothing is designed to erase the local session instead of quietly retaining it.

Fail-closed coverage

Unknown adapter, vehicle, module, profile, account, purchase, or authorization states do not become supported merely because a request reached the software.

Report a vulnerability

Use the private ScanWrench security intake. Include the affected surface, reproducible steps, impact, and a safe way to contact you. Do not include passwords, access tokens, full VINs, payment-card data, identity documents, OEM credentials, or live exploit material that could endanger a vehicle.

Our machine-readable disclosure record is available at /.well-known/security.txt.

Safe testing boundaries

  • Use accounts, adapters, vehicles, and data you own or are explicitly authorized to test.
  • Do not disrupt service, access another person's data, bypass an OEM gateway, or issue unsafe vehicle commands.
  • Stop if testing could move a vehicle, start equipment, disable a safeguard, damage an ECU, expose private data, or affect another user.
  • Give ScanWrench reasonable time to investigate before public disclosure.

What remains external

Independent penetration testing, formal audits, production key-custody review, OEM authorization, and physical adapter and vehicle validation require qualified external parties and real hardware. ScanWrench records these separately from code-level readiness and does not represent them as complete until evidence exists.

Review official correspondence and anti-phishing rules or review the privacy policy.

ScanWrench isa Michai Media product ↗