Security

Conservative scanning by design.

The public scanner is intentionally narrow, while local repository discovery keeps raw source on the user's device and retains only bounded evidence metadata.

Safe public scope

Local repository boundary

Supported files are read in the browser under strict file-count and byte limits. Hidden paths, secret-like files, dependency vendor trees, build output and binaries are excluded. The scanner does not clone a repository, execute code, run hooks, builds or package managers, or transmit file contents and matched snippets. The server accepts only maintained rule tuples and recomputes identity, confidence and risk.

Continuous discovery controls

Recurring scans are available only for an exact hostname and fixed service profile already retained from an authorized scan. Each monitor repeats only its selected HTTPS/443, SMTP STARTTLS/25, IMAPS/993, POP3S/995 or LDAPS/636 profile. Cadence is daily or weekly, each workspace is limited to five current monitors, and authorization expires after 30 days. The scheduler runs in the isolated scanner service and uses the same SSRF and outbound-network controls as manual scans.

Evidence and management separation

Imported public observations, repository declarations, drift events and migration verification results preserve their source authority. Repository evidence remains inferred and does not prove deployment or runtime use. Network drift and migration verification remain scoped to comparable observations of the same hostname, service, port and certificate slot. Ownership, service mapping, migration stage and expected profile remain separately labeled manual assertions.

Private browser workspace

The current workspace is protected by a high-entropy HTTP-only browser cookie and is not a recoverable or shareable team account. It is suitable for private evaluation, not as an enterprise identity control. Workspace APIs are same-origin, no-store and isolated by a keyed non-reversible context.

Secret safety

The scanners do not request private keys, passwords, access tokens or credentials. Public discovery does not enable TLS key logging, capture application content, retain SMTP banners or store packet traces. Local discovery excludes secret-like files before inspection and the import contract rejects arbitrary content.

Responsible use

Visitors must be authorized to assess every submitted target or selected repository, including every recurring scan they enable. Findings describe cryptographic metadata and migration relevance; Cipher Discovery is not performing exploitation or aggressive vulnerability scanning.

Reporting security issues

Please report a security concern to contact@cipherdiscovery.com with enough detail to reproduce the issue. Do not include live credentials or private key material.