Privacy Policy
- Effective Date: June 23, 2026
- Last Updated: June 23, 2026
CipherGap is a post-quantum TLS readiness and cryptographic exposure monitoring service operated by HighGround Labs, LLC (“CipherGap,” “we,” “us,” or “our”).
This Privacy Policy explains what information we collect, how we use it, how we protect it, and what choices you have.
1. Information We Collect
We collect information in the following ways.
Account Information
When you create an account, we may collect:
- Name, if provided.
- Email address.
- Password hash.
- Organization name, if provided.
- Billing plan.
- Account preferences.
- Authentication and session metadata.
We do not store plaintext passwords.
Scan Information
When you use CipherGap to scan or monitor a host, we collect information related to the submitted target and resulting scan activity, including:
- Hostnames submitted for scanning.
- DNS resolution results.
- IP addresses observed during the scan.
- TLS handshake results.
- TLS version and cipher suite information.
- Post-quantum key exchange observations.
- Certificate chain details.
- Certificate expiration details.
- Scan timestamps.
- Scan result history.
- Error and reachability information.
This information is necessary to provide scan results, historical comparison, monitoring, alerts, and reporting.
Billing Information
If you purchase a paid plan, billing information may be processed by our payment provider, Stripe, Inc.
CipherGap does not intentionally store full payment card numbers. Payment processing is handled by our payment processor according to its own security and privacy practices.
Usage and Log Information
We may collect technical information about your use of CipherGap, including:
- IP address.
- Browser type.
- Device information.
- Referring page.
- Pages visited.
- Login events.
- API activity, if applicable.
- Error logs.
- Security logs.
- Approximate location derived from IP address.
We use this information to operate, secure, troubleshoot, and improve the service.
Communications
If you contact us, we may collect:
- Your email address.
- Message content.
- Support request details.
- Any information you choose to provide.
2. How We Use Information
We use collected information to:
- Provide CipherGap services.
- Perform TLS and post-quantum readiness scans.
- Monitor configured hosts.
- Send scan alerts and service notifications.
- Maintain account access.
- Process billing.
- Improve scanner accuracy and reliability.
- Detect abuse, fraud, unauthorized access, or misuse.
- Troubleshoot technical issues.
- Respond to support and security inquiries.
- Comply with legal obligations.
We do not sell personal information.
3. Scan Data and Submitted Hosts
CipherGap is designed to scan internet-facing systems submitted by users.
Users are responsible for ensuring they have authorization to scan submitted hostnames, domains, and systems.
We may use submitted hostnames and scan metadata to provide the service, generate scan history, detect drift, improve scanner reliability, and prevent abuse.
We do not use customer-submitted scan targets to perform invasive testing, exploitation, authentication attempts, denial-of-service testing, or vulnerability exploitation.
4. Cookies and Similar Technologies
CipherGap may use cookies or similar technologies for:
- Authentication.
- Session management.
- Security.
- User preferences.
- Analytics, if enabled.
- Fraud and abuse prevention.
You can control cookies through your browser settings. Disabling cookies may prevent some parts of the service from working properly.
5. Analytics
We may use privacy-conscious analytics to understand product usage, diagnose issues, and improve CipherGap.
Analytics, if used, may include pages visited, device type, browser type, approximate location, and usage events.
We do not intentionally use analytics to collect sensitive personal information.
6. How We Share Information
We may share information with service providers that help us operate CipherGap, such as:
- Cloud hosting providers.
- Database providers.
- Email delivery providers.
- Payment processors.
- Monitoring and logging providers.
- Customer support tools.
- Security and abuse-prevention providers.
These providers are authorized to use information only as needed to provide services to CipherGap.
We may also disclose information if required to:
- Comply with law.
- Respond to lawful requests.
- Enforce our Terms of Service.
- Protect the rights, safety, and security of CipherGap, our users, or others.
- Investigate abuse, fraud, or unauthorized activity.
- Complete a merger, acquisition, financing, or sale of assets.
7. Data Retention
We retain information only as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, enforce agreements, maintain security, and support legitimate business needs.
Typical retention periods:
- Account information: retained while your account is active.
- Scan history: retained while hosts remain monitored or as needed for historical reporting.
- Billing records: retained as required for accounting, tax, and legal purposes.
- Security logs: retained for a limited period for abuse prevention, incident investigation, and service protection.
- Support communications: retained as needed to respond to requests and maintain records.
You may request account deletion by contacting us at privacy@ciphergap.com. Some information may remain in backups, logs, billing records, or legal records for a limited period.
8. Security
We use reasonable administrative, technical, and organizational safeguards to protect information.
These safeguards may include:
- Encryption in transit.
- Access controls.
- Password hashing.
- Least-privilege access.
- Logging and monitoring.
- Secure software development practices.
- Vulnerability management.
- Backup and recovery practices.
No system can be guaranteed completely secure. If we identify a security incident affecting your information, we will respond according to applicable law and our internal incident response procedures.
9. Your Choices
Depending on your location and applicable law, you may have rights to:
- Access personal information we hold about you.
- Correct inaccurate information.
- Delete your account.
- Object to certain processing.
- Request a copy of your information.
- Withdraw consent where processing is based on consent.
To make a request, contact privacy@ciphergap.com.
We may need to verify your identity before completing certain requests.
10. Children’s Privacy
CipherGap is not intended for children under 13, and we do not knowingly collect personal information from children under 13.
If you believe a child has provided us personal information, contact us at privacy@ciphergap.com.
11. International Users
CipherGap is operated from the United States.
If you access CipherGap from outside the United States, your information may be processed in the United States or other countries where our service providers operate.
12. Changes to This Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will update the “Last Updated” date and may notify users through the service, by email, or by another reasonable method.
Your continued use of CipherGap after an updated Privacy Policy becomes effective means you accept the updated policy.
13. Contact
For privacy questions or requests, contact:
CipherGap.com - HighGround Labs, LLC
- Email: privacy@ciphergap.com