Safe scope
- No subdomain enumeration, arbitrary ports, redirects, application crawling or authentication.
- Private, loopback, link-local, metadata, reserved and other special-purpose addresses are blocked.
- DNS is re-checked before connection, the public address is pinned and connection counts and time are bounded.
Secret safety
The scanner does not request private keys, passwords, access tokens or credentials. It does not enable TLS key logging, capture application content or store packet traces.
Responsible use
Visitors must be authorized to assess the submitted target. Findings describe cryptographic metadata and migration relevance; Cipher Discovery is not performing exploitation or aggressive vulnerability scanning.
Reporting security issues
Please report a security concern to contact@cipherdiscovery.com with enough detail to reproduce the issue. Do not include live credentials or private key material.