This page is for the person who has to approve PathWolf before it touches your accounts. It states what is in place today and what is not, with the documents that back each claim. Vagueness reads as absence, so where something does not exist we say so.
Certifications and guarantees
PathWolf holds no SOC 2, no ISO 27001 and no other security certification, and has commissioned no independent audit or penetration test. We publish no availability guarantee, no uptime figure and no service-level commitment, and we run no paid bug-bounty programme.
What exists instead is a short, named set of sub-processors, consent enforced by category, deliverability protected by design, and a published route for reporting a vulnerability. We would rather state that than imply a posture we cannot evidence.
Accessibility
The interface is built to WCAG 2.1 AA: semantic structure, full keyboard operability, visible focus, dialogs that trap and then restore focus, and honoured reduced-motion settings. No independent accessibility audit has been commissioned; our Accessibility Statement records what has and has not been verified.
Reporting a vulnerability
There is a published route for reporting a security vulnerability. It sets out what is in scope, what good-faith research means here, and what a reporter can expect in return. We offer no reward for disclosure; we do commit to a considered reply, and a named person owns the response.
Your data, on request
A person can ask what personal data is held about them, ask for it to be corrected, and ask for it to be deleted. Business customers can obtain data-processing terms before any customer data is processed. Both routes are set out in the documents below.