AUTONOMOUS SECURITY TESTING · APPLICATION · CLOUD · NETWORKEST. 2025
SINGLE TENANT · ENCRYPTED · NEVER USED FOR TRAINING

Your findings are yours. Nobody else sees them.

Letting something test your systems only works if the boundary around your data is absolute and the record of what it did is complete. Both are built in, not settings.

ISOLATION
Yours alone
Your work never shares a boundary with another customer.
ENCRYPTION
Locked at rest
Credentials are vaulted and the reasoning trail is stored encrypted.
NO TRAINING
Never pooled
Not sold on, and never fed into any shared or third party model.
YOUR CALL
Delete anytime
You set the retention window and can remove an engagement outright.
01DATA HANDLING

Four commitments.

ISOLATION

Single tenant by default

Your engagements, credentials and knowledge graph never share a boundary with another customer. There is no shared corpus into which your estate could leak, because the architecture does not have one.

ENCRYPTION

Encrypted at rest and in transit

Credentials sit in a vault rather than in configuration, and the agent's reasoning trail is stored encrypted rather than as plain text, so a database copy is not a transcript of your weaknesses.

NO TRAINING, NO RESALE

Never used to improve a model

Your findings are not pooled with other customers', not sold on as threat intelligence, and not fed back into any shared model. This is written into the agreement, not just the marketing.

CUSTOMER CONTROL

You set retention and deletion

Choose the retention window, export what you need in a portable form, and delete an engagement and its graph outright at any time. Deletion removes the evidence too, not just the index.

02SAFETY MODEL

The agent cannot exceed what you authorised.

Scope is not advisory. Every outbound request is checked against the authorised set before it is issued, and refusals are recorded alongside successes.

SCOPE CHECKAUDIT LOG
GET app.your-domain.com/api/v1/accountsALLOW
POST app.your-domain.com/loginALLOW
GET unrelated-third-party.example/BLOCK
DELETE app.your-domain.com/api/v1/accounts/1BLOCK
2 REFUSED · OUT OF SCOPE HOST · DESTRUCTIVE ACTION · BOTH LOGGED WITH REASON
Hard scope enforcement

Targets are resolved and pinned at provisioning. Requests to anything outside the authorised set are refused rather than warned about.

Rebinding and drift protection

A target that changes underneath the engagement cannot be used to redirect the agent at infrastructure you never authorised.

Destructive action guards

Operations that would damage data or disrupt availability are blocked by default, and every block is logged with its reason. Coverage is never traded for uptime.

Complete, replayable audit log

Every request, decision and refusal is written down in order, so you can prove exactly what was touched and when, to an auditor or to your own board.

Start with one of your assets.

The enquiry form asks only what we need to write a scope: the asset, the surface it sits on, and who authorises testing on it.

GO TO CONTACT
WHAT YOU GET BACK
Scope document2 BUSINESS DAYS
Safety constraints in writingWITH THE SCOPE
First verified findingsHOURS FROM START
Audit logWITH EVERY RUN

Nothing you submit is shared outside Cipher, and enquiry details are never used to train a model.