Scan data
For an anonymous scan, we process the submitted public hostname, eligible public endpoint addresses, public certificate material, public TLS observations, authorization attestation and technical metadata required for evidence, coverage, safety and abuse prevention.
What we do not collect for scanning
We do not request private keys, passwords, credentials or access tokens. The scanner does not retrieve application content or authenticate to the target.
Retention
Anonymous report data is designed to expire no later than 24 hours after a scan reaches a terminal state. Operational aggregate metrics may be retained only without target, certificate or visitor identifiers.
Analytics
Analytics is optional and disabled when no measurement identifier is configured. When enabled, it records bounded product events and does not include scan hostnames, certificate data or report contents.
Contact
Privacy questions can be sent to contact@cipherdiscovery.com.