Privacy Policy

  • Effective Date: June 23, 2026
  • Last Updated: June 23, 2026

CipherGap is a post-quantum TLS readiness and cryptographic exposure monitoring service operated by HighGround Labs, LLC (“CipherGap,” “we,” “us,” or “our”).

This Privacy Policy explains what information we collect, how we use it, how we protect it, and what choices you have.

1. Information We Collect

We collect information in the following ways.

Account Information

When you create an account, we may collect:

  • Name, if provided.
  • Email address.
  • Password hash.
  • Organization name, if provided.
  • Billing plan.
  • Account preferences.
  • Authentication and session metadata.

We do not store plaintext passwords.

Scan Information

When you use CipherGap to scan or monitor a host, we collect information related to the submitted target and resulting scan activity, including:

  • Hostnames submitted for scanning.
  • DNS resolution results.
  • IP addresses observed during the scan.
  • TLS handshake results.
  • TLS version and cipher suite information.
  • Post-quantum key exchange observations.
  • Certificate chain details.
  • Certificate expiration details.
  • Scan timestamps.
  • Scan result history.
  • Error and reachability information.

This information is necessary to provide scan results, historical comparison, monitoring, alerts, and reporting.

Billing Information

If you purchase a paid plan, billing information may be processed by our payment provider, Stripe, Inc.

CipherGap does not intentionally store full payment card numbers. Payment processing is handled by our payment processor according to its own security and privacy practices.

Usage and Log Information

We may collect technical information about your use of CipherGap, including:

  • IP address.
  • Browser type.
  • Device information.
  • Referring page.
  • Pages visited.
  • Login events.
  • API activity, if applicable.
  • Error logs.
  • Security logs.
  • Approximate location derived from IP address.

We use this information to operate, secure, troubleshoot, and improve the service.

Communications

If you contact us, we may collect:

  • Your email address.
  • Message content.
  • Support request details.
  • Any information you choose to provide.

2. How We Use Information

We use collected information to:

  • Provide CipherGap services.
  • Perform TLS and post-quantum readiness scans.
  • Monitor configured hosts.
  • Send scan alerts and service notifications.
  • Maintain account access.
  • Process billing.
  • Improve scanner accuracy and reliability.
  • Detect abuse, fraud, unauthorized access, or misuse.
  • Troubleshoot technical issues.
  • Respond to support and security inquiries.
  • Comply with legal obligations.

We do not sell personal information.

3. Scan Data and Submitted Hosts

CipherGap is designed to scan internet-facing systems submitted by users.

Users are responsible for ensuring they have authorization to scan submitted hostnames, domains, and systems.

We may use submitted hostnames and scan metadata to provide the service, generate scan history, detect drift, improve scanner reliability, and prevent abuse.

We do not use customer-submitted scan targets to perform invasive testing, exploitation, authentication attempts, denial-of-service testing, or vulnerability exploitation.

4. Cookies and Similar Technologies

CipherGap may use cookies or similar technologies for:

  • Authentication.
  • Session management.
  • Security.
  • User preferences.
  • Analytics, if enabled.
  • Fraud and abuse prevention.

You can control cookies through your browser settings. Disabling cookies may prevent some parts of the service from working properly.

5. Analytics

We may use privacy-conscious analytics to understand product usage, diagnose issues, and improve CipherGap.

Analytics, if used, may include pages visited, device type, browser type, approximate location, and usage events.

We do not intentionally use analytics to collect sensitive personal information.

6. How We Share Information

We may share information with service providers that help us operate CipherGap, such as:

  • Cloud hosting providers.
  • Database providers.
  • Email delivery providers.
  • Payment processors.
  • Monitoring and logging providers.
  • Customer support tools.
  • Security and abuse-prevention providers.

These providers are authorized to use information only as needed to provide services to CipherGap.

We may also disclose information if required to:

  • Comply with law.
  • Respond to lawful requests.
  • Enforce our Terms of Service.
  • Protect the rights, safety, and security of CipherGap, our users, or others.
  • Investigate abuse, fraud, or unauthorized activity.
  • Complete a merger, acquisition, financing, or sale of assets.

7. Data Retention

We retain information only as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs.

Typical retention periods:

  • Account information: retained while your account is active.
  • Scan history: retained while hosts remain monitored or as needed for historical reporting.
  • Billing records: retained as required for accounting, tax, and legal purposes.
  • Security logs: retained for a limited period for abuse prevention, incident investigation, and service protection.
  • Support communications: retained as needed to respond to requests and maintain records.

You may request account deletion by contacting us at privacy@ciphergap.com. Some information may remain in backups, logs, billing records, or legal records for a limited period.

8. Security

We use reasonable administrative, technical, and organizational safeguards to protect information.

These safeguards may include:

  • Encryption in transit.
  • Access controls.
  • Password hashing.
  • Least-privilege access.
  • Logging and monitoring.
  • Secure software development practices.
  • Vulnerability management.
  • Backup and recovery practices.

No system can be guaranteed completely secure. If we identify a security incident affecting your information, we will respond according to applicable law and our internal incident response procedures.

9. Your Choices

Depending on your location and applicable law, you may have rights to:

  • Access personal information we hold about you.
  • Correct inaccurate information.
  • Delete your account.
  • Object to certain processing.
  • Request a copy of your information.
  • Withdraw consent where processing is based on consent.

To make a request, contact privacy@ciphergap.com.

We may need to verify your identity before completing certain requests.

10. Children’s Privacy

CipherGap is not intended for children under 13, and we do not knowingly collect personal information from children under 13.

If you believe a child has provided us personal information, contact us at privacy@ciphergap.com.

11. International Users

CipherGap is operated from the United States.

If you access CipherGap from outside the United States, your information may be processed in the United States or other countries where our service providers operate.

12. Changes to This Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will update the “Last Updated” date and may notify users through the service, by email, or by another reasonable method.

Your continued use of CipherGap after an updated Privacy Policy becomes effective means you accept the updated policy.

13. Contact

For privacy questions or requests, contact:

CipherGap.com - HighGround Labs, LLC

  • Email: privacy@ciphergap.com