Security & Trust

Redhunter runs offensive tooling against real systems, so control and accountability are built into the engine — not bolted on.

Scope enforcement

We never run a hunt against a target you haven't proven you own. Ownership is verified by DNS TXT record, a file at /.well-known/redhunter-verify.txt, or a read-only cloud IAM role for AWS, GCP, or Azure. Per-asset scope rules and allow/deny lists bound every hunt to what you authorize.

Agent controls

  • Hard per-asset rate limits and backoff rules
  • An iteration cap on the reasoning loop
  • A kill switch you can hit on any hunt in one click
  • Scope guards that refuse any target outside verified ownership
  • An append-only audit log of every request the agent sends

Where your data lives

Two deployment options. Hosted: we run the engine in our cloud against your authorized scope. Self-hosted: we provide a container you run in your own VPC, and your traffic never touches our network. The Console reads from your engine state.

Compliance

We sign DPAs, BAAs, and custom MSAs today, and the self-hosted option keeps all traffic and data inside your own environment. SOC 2 is on our roadmap — we are not yet SOC 2 certified.

Reporting an issue

Found a vulnerability in Redhunter itself? We want to hear about it. Email security@redhunter.ai with details and reproduction steps.