Security

  • Effective Date: June 23, 2026
  • Last Updated: June 23, 2026

Security is central to CipherGap.

CipherGap helps users evaluate externally observable TLS and post-quantum readiness. We also apply practical security controls to protect the service, customer accounts, scan data, and operational infrastructure.

This page describes our current security practices.

1. Scope

This Security page applies to the CipherGap application, scanner infrastructure, account systems, and supporting cloud services operated by Company Legal Name.

It does not apply to third-party systems scanned by CipherGap users.

2. Data We Protect

CipherGap is designed to minimize the amount of sensitive information we collect.

The primary data we protect includes:

  • Account email addresses.
  • Authentication data.
  • Submitted hostnames.
  • Scan results.
  • Monitored host configuration.
  • Alert settings.
  • Billing plan metadata.
  • Security and application logs.
  • Support communications.

CipherGap does not intentionally collect passwords in plaintext, payment card numbers, private keys, source code, protected health information, or customer secrets.

Users should not submit sensitive secrets to CipherGap.

3. Encryption

CipherGap uses encryption in transit for access to the service.

Where supported by our infrastructure and providers, sensitive data is encrypted at rest.

Passwords are not stored in plaintext.

4. Access Control

Access to production systems is limited to authorized personnel and service accounts with a business need.

We aim to follow least-privilege principles for administrative access.

Access may be reviewed, changed, or revoked based on role, operational need, and security risk.

5. Authentication

CipherGap account authentication is designed to protect user access and prevent unauthorized account use.

Security features may include:

  • Secure password handling.
  • Session controls.
  • Account activity monitoring.
  • Abuse and brute-force protections.
  • Administrative access restrictions.

Additional authentication features, including multi-factor authentication and enterprise SSO, may be added as the product matures.

6. Logging and Monitoring

CipherGap collects application, infrastructure, and security logs to support:

  • Availability monitoring.
  • Abuse detection.
  • Incident investigation.
  • Error troubleshooting.
  • Security review.
  • Operational reliability.

Logs are retained for a limited period based on operational, security, and legal needs.

7. Vulnerability Management

We use a risk-based approach to vulnerability management.

This may include:

  • Dependency review.
  • Security updates.
  • Code review.
  • Infrastructure hardening.
  • External vulnerability reports.
  • Remediation tracking.
  • Security testing.

Security issues are prioritized based on severity, exploitability, exposure, affected data, and operational impact.

8. Secure Development

CipherGap is developed using security-conscious engineering practices.

These may include:

  • Review of security-sensitive code.
  • Input validation.
  • Authentication and authorization checks.
  • Secret management.
  • Dependency updates.
  • Separation of environments.
  • Defensive logging.
  • Scanner safety controls.

9. Scanner Safety

CipherGap performs lightweight external TLS checks.

CipherGap does not intentionally perform:

  • Exploitation.
  • Credential attacks.
  • Denial-of-service testing.
  • Application-layer attack testing.
  • Authentication bypass attempts.
  • Destructive testing.
  • Data extraction from scanned systems.

Users are responsible for scanning only systems they own, administer, or are authorized to assess.

10. Data Retention and Deletion

CipherGap retains account, scan, billing, and log data only as long as reasonably necessary to provide the service, preserve security, meet legal obligations, and support business operations.

Users may request account deletion by contacting support@ciphergap.com or privacy@ciphergap.com.

Some information may remain temporarily in backups, logs, billing records, or legal records.

11. Incident Response

If we identify a security incident, we will investigate, contain, remediate, and notify affected users where appropriate or legally required.

Incident response may include:

  • Triage.
  • Containment.
  • Evidence preservation.
  • Root cause analysis.
  • Remediation.
  • User notification.
  • Control improvements.

12. Third-Party Providers

CipherGap may rely on third-party providers for hosting, email delivery, payment processing, logging, monitoring, analytics, and support.

We select providers based on operational need, security relevance, and business suitability.

13. Compliance Status

CipherGap is an early-stage security product.

Unless explicitly stated in a signed agreement, CipherGap does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or other formal certification.

As the product matures, we may add formal security reviews, compliance reporting, and enterprise assurance materials.

14. Security Contact

To report a security issue, use our Vulnerability Disclosure Policy or contact:

security@ciphergap.com