Trust & Security
Last updated: July 12, 2026
Pathbreak maps how an attacker could escalate privileges inside your cloud. That makes the way we handle your access and your data as important as the product itself. This page explains, in plain terms, how Pathbreak is built to be trusted with it. Pathbreak is in private preview, and we keep this page current as the product and our assurances grow.
Least-privilege, read-only access
Pathbreak connects to your cloud with least-privilege, read-only access that you grant and control. You scope it to the accounts you choose, and you can revoke it at any time. We ask for no more than we need to map and validate attack paths.
Your configuration, never your data
Pathbreak reads identity and policy metadata, such as IAM policies, roles, trust relationships and resource configuration, to map how privileges could be escalated. It does not read your object storage, database contents, secrets, or workload data. We work from the control plane, not your data plane.
The agent is read-only by design
Pathbreak validates an attack path by resolving the real authorization end to end, not by exploiting it. The agent is read-only by construction: it confirms whether a chain is exploitable, and nothing is executed against your resources. When it finds a path, it hands you the exact change that severs it, so you decide what to apply.
Isolation and encryption
Your data is kept isolated and encrypted in transit and at rest, to a best-in-class standard. Access to it inside Pathbreak is limited to what is needed to operate the service.
Your data stays yours
We do not use your data to train models. Exposures and attack paths from your environment are confidential to you. We retain them only as long as needed to provide the service and under the terms of your agreement, and you can ask us to delete them.
Runs on the model you choose
Pathbreak's agent is powered by a large language model, and you decide which one and where it runs. Point it at OpenAI, at Amazon Bedrock inside your own AWS account, or at any OpenAI-compatible endpoint you host yourself. Your provider credentials are stored encrypted. If you would rather your cloud's metadata never leave infrastructure you control, run the model in your own account or on your own endpoint.
Single sign-on and least-privilege roles
Access to Pathbreak is invite-only. Bring your own identity provider with SAML single sign-on, and assign role-based permissions so each teammate sees only the accounts and actions they should. It is the same least-privilege posture we apply to your cloud, applied to the product itself.
We hold our own platform to the same standard
We harden our own infrastructure and welcome reports from security researchers. See our Security Policy and machine-readable security.txt for how to reach us and what is in scope.
Data protection and privacy
How we handle personal data is set out in our Privacy Policy, and the terms of using Pathbreak are in our Terms of Service. Pathbreak Ltd is registered in England and Wales, company number 17265710.
Questions
For anything about security or trust, contact [email protected]. For everything else, [email protected].