Security
- Effective Date: June 23, 2026
- Last Updated: June 23, 2026
Security is central to CipherGap.
CipherGap helps users evaluate externally observable TLS and post-quantum readiness. We also apply practical security controls to protect the service, customer accounts, scan data, and operational infrastructure.
This page describes our current security practices.
1. Scope
This Security page applies to the CipherGap application, scanner infrastructure, account systems, and supporting cloud services operated by Company Legal Name.
It does not apply to third-party systems scanned by CipherGap users.
2. Data We Protect
CipherGap is designed to minimize the amount of sensitive information we collect.
The primary data we protect includes:
- Account email addresses.
- Authentication data.
- Submitted hostnames.
- Scan results.
- Monitored host configuration.
- Alert settings.
- Billing plan metadata.
- Security and application logs.
- Support communications.
CipherGap does not intentionally collect passwords in plaintext, payment card numbers, private keys, source code, protected health information, or customer secrets.
Users should not submit sensitive secrets to CipherGap.
3. Encryption
CipherGap uses encryption in transit for access to the service.
Where supported by our infrastructure and providers, sensitive data is encrypted at rest.
Passwords are not stored in plaintext.
4. Access Control
Access to production systems is limited to authorized personnel and service accounts with a business need.
We aim to follow least-privilege principles for administrative access.
Access may be reviewed, changed, or revoked based on role, operational need, and security risk.
5. Authentication
CipherGap account authentication is designed to protect user access and prevent unauthorized account use.
Security features may include:
- Secure password handling.
- Session controls.
- Account activity monitoring.
- Abuse and brute-force protections.
- Administrative access restrictions.
Additional authentication features, including multi-factor authentication and enterprise SSO, may be added as the product matures.
6. Logging and Monitoring
CipherGap collects application, infrastructure, and security logs to support:
- Availability monitoring.
- Abuse detection.
- Incident investigation.
- Error troubleshooting.
- Security review.
- Operational reliability.
Logs are retained for a limited period based on operational, security, and legal needs.
7. Vulnerability Management
We use a risk-based approach to vulnerability management.
This may include:
- Dependency review.
- Security updates.
- Code review.
- Infrastructure hardening.
- External vulnerability reports.
- Remediation tracking.
- Security testing.
Security issues are prioritized based on severity, exploitability, exposure, affected data, and operational impact.
8. Secure Development
CipherGap is developed using security-conscious engineering practices.
These may include:
- Review of security-sensitive code.
- Input validation.
- Authentication and authorization checks.
- Secret management.
- Dependency updates.
- Separation of environments.
- Defensive logging.
- Scanner safety controls.
9. Scanner Safety
CipherGap performs lightweight external TLS checks.
CipherGap does not intentionally perform:
- Exploitation.
- Credential attacks.
- Denial-of-service testing.
- Application-layer attack testing.
- Authentication bypass attempts.
- Destructive testing.
- Data extraction from scanned systems.
Users are responsible for scanning only systems they own, administer, or are authorized to assess.
10. Data Retention and Deletion
CipherGap retains account, scan, billing, and log data only as long as reasonably necessary to provide the service, preserve security, meet legal obligations, and support business operations.
Users may request account deletion by contacting support@ciphergap.com or privacy@ciphergap.com.
Some information may remain temporarily in backups, logs, billing records, or legal records.
11. Incident Response
If we identify a security incident, we will investigate, contain, remediate, and notify affected users where appropriate or legally required.
Incident response may include:
- Triage.
- Containment.
- Evidence preservation.
- Root cause analysis.
- Remediation.
- User notification.
- Control improvements.
12. Third-Party Providers
CipherGap may rely on third-party providers for hosting, email delivery, payment processing, logging, monitoring, analytics, and support.
We select providers based on operational need, security relevance, and business suitability.
13. Compliance Status
CipherGap is an early-stage security product.
Unless explicitly stated in a signed agreement, CipherGap does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or other formal certification.
As the product matures, we may add formal security reviews, compliance reporting, and enterprise assurance materials.
14. Security Contact
To report a security issue, use our Vulnerability Disclosure Policy or contact:
security@ciphergap.com