Who you are trusting.
Webcuris asks you to point a scanner at systems you care about, and sometimes to connect a read-only credential to a cloud account. Every one of those is a decision about trusting whoever runs it. This page is that answer, and nothing else.
A name, and where to find it.
Webcuris is operated by Mayank Jain, established in India.
Webcuris is run by one person rather than a registered company. That is stated here because you would work it out eventually, and because it is the relevant fact when you are deciding what to connect: there is no support organisation behind this, and the response times reflect that.
- Founder and operator
- Mayank Jain
- Established in
- India
- Report a vulnerability in this service
- security@webcuris.com
Data-protection contact
Complaints about how your personal data is handled go to Mayank Jain, the Grievance Officer published under India’s DPDP Act at privacy@webcuris.com. That is a distinct role from operating the service, which is why it is listed separately rather than folded into the box above.
Every claim on this site points at its own evidence.
A security vendor asking to be trusted should be checkable rather than reassuring. These are the four claims that matter most, each with the page that lets you verify it — including the one that lists what this product cannot do.
Every finding carries a confidence level
Visible on any scan result and in every export.
What confidence meansThe limitations are published before you sign up
No SOC 2, no third-party penetration test, compliance mappings are context rather than audit evidence.
Security PolicyScanning is authorised, and passive by default
Checks that go beyond an ordinary browser visit stay locked until domain ownership is proven.
What runs against whatWhat is stored, and for how long, is written down
Including commit author names read from scanned repositories — data about people who never signed up.
Privacy and retentionSmall, and not pretending otherwise.
Webcuris is not a large security organisation, and the site does not imply one. There is no SOC 2 report, no third-party penetration test of this service, and no 24/7 response desk. Those are stated here and on the Security Policy because you would find out eventually, and finding out later is worse for both of us.
What it does have is a scanner that says how sure it is, limitations written down in advance, and a named person to complain to. For a great many teams that is a better trade than a louder tool that is confident about everything.
Keep reading