← Back to CipherGuardia

Privacy Policy

Last updated August 2026 · CipherGuardia (Attack Surface Management)

What this covers

CipherGuardia is an external attack surface management platform. You give us a domain you are authorised to assess; we map its internet-facing assets and test them for vulnerabilities. This policy explains what we collect, why, and what we never do with it.

What we collect

  • Account data. Your email address, a password hash (PBKDF2 — we never store the password itself), and your plan. If you sign in with Google we additionally store the Google account identifier, and the display name and profile picture Google returns.
  • Scan data. The domains you submit and everything the scan discovers about them: subdomains, web applications, IP addresses, TLS certificates, cloud storage endpoints, and the findings raised against them.
  • Authorisation records. Because scanning requires permission, we log who submitted each scan, from which IP address, with which browser, and when. These records exist to establish that a scan was authorised.
  • Payment records. Plan, amount, currency and the payment reference from our processor. Card and UPI details are handled entirely by Razorpay and never reach our servers.

Credentials found during a scan

Our scanners look for secrets that are already publicly exposed on your assets — API keys committed into front-end code, for example. These are stored redacted: enough of the value to identify which key is leaking, never enough to use it. We do not attempt to authenticate with anything we find.

How we use it

To run the scans you request, show you the results, bill you for the plan you chose, and keep the platform secure and within its cost limits. That is the complete list.

We do not sell your data, and we do not share your findings with anyone. We do not use your scan results to train models or to build a commercial dataset.

Google sign-in

If you sign in with Google we request only the openid, email and profile scopes. We use them to identify your account and nothing else. We never request access to your Gmail, Drive, Calendar, contacts, or any other Google service, and we hold no Google access token after sign-in completes.

Retention and deletion

Scan data is kept while your account is open so you can compare against previous scans. Email your request to support@cipherguardia.com and we will delete your account and its scan data. Authorisation logs and payment records are kept longer where we are required to retain them.

Contact

Questions about this policy, or a data request: support@cipherguardia.com.