PRODUCT
Security and data handling
Straight answers for the questions procurement and security teams actually ask. Cipherscan reads only negotiated TLS handshake metadata, never application data, credentials, or private network access, and stores just enough to generate your readiness report. This page covers exactly what's collected, how it's secured, and what never leaves your systems.
Is anything installed on our infrastructure?
Not for hosted scanning of public domains. Nothing is installed unless you deliberately download the Cipherscan CLI to scan private, non-public infrastructure.
What data does the CLI upload?
Only the scan results: which hosts were checked, which algorithms were negotiated, and pass or fail status per host. It does not upload traffic contents, credentials, or unrelated system data.
What is explicitly excluded from a scan?
Cipherscan reads negotiated TLS handshake parameters only. It does not access application data, file systems, credentials, or traffic payloads.
How long is scan data retained?
Scan results are retained for as long as your account is active, so you can track readiness over time. You can request deletion of your account and its data at any time.
How is data segregated for consultants managing multiple clients?
Each client environment is isolated within your account. Consultants can view results per client without those clients seeing each other’s data.
Where is Ciphersound hosted, and what security practices apply?
Ciphersound runs on standard cloud infrastructure with encryption in transit and at rest, and follows the same security practices established by the team behind Anvil Secure.