Safe public scope
- No subdomain enumeration, arbitrary ports, redirects, application crawling or authentication.
- Private, loopback, link-local, metadata, reserved and other special-purpose addresses are blocked.
- DNS is re-checked before every connection, the public address is pinned and connection counts and time are bounded.
- SMTP sends only a fixed EHLO identity and STARTTLS command. It never authenticates or submits mail. Direct-TLS profiles send no application commands.
Local repository boundary
Supported files are read in the browser under strict file-count and byte limits. Hidden paths, secret-like files, dependency vendor trees, build output and binaries are excluded. The scanner does not clone a repository, execute code, run hooks, builds or package managers, or transmit file contents and matched snippets. The server accepts only maintained rule tuples and recomputes identity, confidence and risk.
Continuous discovery controls
Recurring scans are available only for an exact hostname and fixed service profile already retained from an authorized scan. Each monitor repeats only its selected HTTPS/443, SMTP STARTTLS/25, IMAPS/993, POP3S/995 or LDAPS/636 profile. Cadence is daily or weekly, each workspace is limited to five current monitors, and authorization expires after 30 days. The scheduler runs in the isolated scanner service and uses the same SSRF and outbound-network controls as manual scans.
Evidence and management separation
Imported public observations, repository declarations, drift events and migration verification results preserve their source authority. Repository evidence remains inferred and does not prove deployment or runtime use. Network drift and migration verification remain scoped to comparable observations of the same hostname, service, port and certificate slot. Ownership, service mapping, migration stage and expected profile remain separately labeled manual assertions.
Private browser workspace
The current workspace is protected by a high-entropy HTTP-only browser cookie and is not a recoverable or shareable team account. It is suitable for private evaluation, not as an enterprise identity control. Workspace APIs are same-origin, no-store and isolated by a keyed non-reversible context.
Secret safety
The scanners do not request private keys, passwords, access tokens or credentials. Public discovery does not enable TLS key logging, capture application content, retain SMTP banners or store packet traces. Local discovery excludes secret-like files before inspection and the import contract rejects arbitrary content.
Responsible use
Visitors must be authorized to assess every submitted target or selected repository, including every recurring scan they enable. Findings describe cryptographic metadata and migration relevance; Cipher Discovery is not performing exploitation or aggressive vulnerability scanning.
Reporting security issues
Please report a security concern to contact@cipherdiscovery.com with enough detail to reproduce the issue. Do not include live credentials or private key material.