Legal

Privacy

Cipher Discovery minimizes the data needed to provide an anonymous public cryptographic exposure report.

Scan data

For an anonymous scan, we process the submitted public hostname, eligible public endpoint addresses, public certificate material, public TLS observations, authorization attestation and technical metadata required for evidence, coverage, safety and abuse prevention.

What we do not collect for scanning

We do not request private keys, passwords, credentials or access tokens. The scanner does not retrieve application content or authenticate to the target.

Retention

Anonymous report data is designed to expire no later than 24 hours after a scan reaches a terminal state. Operational aggregate metrics may be retained only without target, certificate or visitor identifiers.

Analytics

Analytics is optional and disabled when no measurement identifier is configured. When enabled, it records bounded product events and does not include scan hostnames, certificate data or report contents.

Contact

Privacy questions can be sent to contact@cipherdiscovery.com.