Skip to content

Security at Patcharo

How Patcharo protects the data it holds, and how to report a vulnerability.

Last updated 30 Sept 2026

Identity and sessions

Accounts are managed by Supabase Auth. E-mail addresses are verified through single-use links exchanged server-side; passwords need at least 12 characters with upper case, lower case, a digit and a symbol. Every protected page and every action re-checks the identity on the server; nothing relies on the browser's word.

Tenant isolation

Every workspace table is protected by row-level security. Signed-in users hold no write privilege on tenant tables: each change goes through a database function that checks the caller's membership and role (owner, admin, analyst, viewer), validates the input, enforces the plan limits and writes the audit log in the same transaction. Invitation tokens are stored hashed and expire. MSSP accounts hold no customer asset data; each customer stays an isolated workspace. Privileges and policies are verified by automated checks at every schema change.

What Patcharo stores

For a workspace: the assets (vendor, product, version, patch level, model, labels, environment, criticality), the technology and IP address watches, remediation decisions, the members' e-mail addresses and roles, and the audit log. Watched IP addresses are never written to logs nor to the audit trail. The vulnerability intelligence (CVE, CISA KEV, EPSS, CERT-FR, vendor statements) is public data; the public site publishes it without any customer data.

Platform and transport

The application and the public site run on Cloudflare; the database and authentication on Supabase (PostgreSQL). Transport is TLS only with HSTS. Responses carry strict security headers (content security policy forbidding framing, nosniff, referrer and permissions policies), state-changing requests are rejected when they do not come from the site, redirects are restricted to safe destinations and CSV exports are protected against formula injection. Server-side secrets never reach the browser: the deployed bundle is scanned for secret values before every deployment.

Integrity of the intelligence

Sources are read from their official endpoints; every snapshot is checksummed and carries its parser version and retrieval time. Whether a version is affected is decided by a deterministic matcher, never by a language model; a missing fact stays Unknown. A wrong reading of a source is corrected at the next synchronisation once the parser is fixed.

What Patcharo does not claim

Patcharo holds no ISO 27001, SOC 2 or ANSSI certification or qualification and has published no third-party penetration test to date. This page states what is in place; it will change when that does.

Report a vulnerability

Write to the security address below. Include the address concerned, the steps to reproduce and the impact you observed. We read every report and answer from the same address; please leave us a reasonable time to fix before any publication. There is no bug bounty programme at this time.

security@patcharo.comsecurity.txtContact