Legal

Privacy

Cipher Discovery minimizes the data needed to provide an anonymous public cryptographic exposure report and an optional private ownership workspace.

Scan data

For an anonymous scan, we process the submitted public hostname and selected service, eligible public endpoint addresses, public certificate material, public TLS observations, authorization attestation and technical metadata required for evidence, coverage, safety and abuse prevention.

Local repository discovery

Repository files are inspected locally in the browser and are not uploaded. If you explicitly import a result, we retain only the source label, scanner and rule versions, bounded coverage counters, SHA-256 digests of fully inspected relative paths, rule identifiers, categories, languages, relative finding paths, line and column locations, allowlisted symbols and SHA-256 file digests. Path digests may reveal predictable names and are comparison metadata, not anonymization. We do not retain repository archives, file contents, matched snippets, Git history, remote URLs or author identities.

Private workspace data

If you explicitly add a report, CBOM or local repository manifest to the ownership workspace, we retain its normalized cryptographic assets, source-specific evidence, findings, risk provenance and the application, service, environment, owner contact, business context, dependencies, migration status and change reasons you enter. If you create a migration verification plan, we also retain its expected public certificate profile, stage, revisions and immutable comparison results with baseline and current public evidence. The workspace is protected by an opaque browser cookie; only a keyed, non-reversible context is stored by the service.

An optional remediation task URL is retained with its previous and new values in the workspace audit history. Do not enter secrets, credentials or signed links. We do not fetch or synchronize the external task; following the link opens the external service without a referrer. Its own privacy terms then apply.

When you download a discovery snapshot, unsigned or signed, the private archive contains retained inventory and public-source evidence plus bounded recent management audit, drift and verification records. This may include owner contact and change reasons you entered. The signer receives only the bounded manifest, not the inventory payload. Export does not extend workspace retention, but a downloaded copy is then under your control and should be handled as sensitive data.

Continuous discovery data

If you explicitly enable recurring discovery, we retain the exact imported hostname, selected HTTPS, SMTP STARTTLS, IMAPS, POP3S or LDAPS service and fixed port, daily or weekly cadence, 30-day authorization window, scan outcomes, immutable comparison snapshots and evidence-backed drift events. Each monitor repeats only that exact profile. Pausing stops future scheduling without deleting retained evidence. Background scans do not extend workspace retention.

What we do not collect for scanning

We do not request private keys, passwords, credentials or access tokens. The public scanner does not retrieve application content or authenticate to the target. SMTP greeting and capability text are parsed only to reach STARTTLS and are not retained. The repository manifest contract cannot include arbitrary source content.

Retention

Anonymous report data is designed to expire no later than 24 hours after a scan reaches a terminal state. Data explicitly retained in a private browser workspace, including repository import, monitor, drift and verification history, expires after 90 days without workspace activity. Operational aggregate metrics may be retained only without target, certificate, workspace or visitor identifiers.

Analytics

Analytics is optional and disabled when no measurement identifier is configured. When enabled, it records bounded product events and does not include scan hostnames, certificate data, repository paths or digests, owner data, workspace contents or report contents.

Contact

Privacy questions can be sent to contact@cipherdiscovery.com.