Scanning policy

cipher-scout.com is the network identity of an authorised security scanning service operated by ExeQuantum. Every connection from one of our addresses is made on behalf of a customer who owns or is authorised to test the systems being scanned and who has asked us to assess them. We do not scan systems we have not been asked to scan.

What the scans do

Our scans check how a customer's internet-facing systems respond: which services are reachable, how they are configured and how their encryption is set up. The scans are read-only. They do not attempt to log in, exploit a weakness, change data or disrupt a service. They are paced so that a scanned system sees a low, steady rate of connections rather than a burst.

How to recognise our traffic

Every address we scan from has a name under cipher-scout.com, and every such name points back to the same address. To check an address that has contacted you:

  1. Look up the reverse record for the address. It will be a name of the form scanN.cipher-scout.com, where N is a number.
  2. Look up that name. It will resolve to the address you started with.
  3. Open https:// followed by that name in a browser. You will find this policy, the address and name you just checked and the contact below.

If all three steps agree, the traffic came from us. An address whose reverse record names cipher-scout.com but whose name does not resolve back to it is not ours, and we would like to hear about it at the contact below.

We never scan from an address that does not have this two-way record.

How to allow our scans

If you are a customer, or you host systems for one, and you want our scans to reach you through a firewall or an intrusion prevention system, allow inbound connections from the addresses that names of the form scanN.cipher-scout.com resolve to. Addresses are added and retired over time and each one is announced on its own name before it is used, so rules based on the names stay correct where rules based on fixed addresses go stale.

How to request exclusion

If you believe your systems are being scanned without authorisation, or you do not want them scanned even though a customer has asked us to, write to the contact below with the addresses or names you want excluded and the address of ours that contacted you. We will confirm receipt, check the authorisation on record and either stop or explain why the scan is authorised. Exclusion requests from the owner of a system are honoured.

Abuse contact

abuse@cipher-scout.com

We respond to every message within 2 business days. Please include the date and time of the traffic you saw, the address it came from and the address it reached, so we can match it to a scan. Logs or packet captures are welcome but not required. The same contact is published in /.well-known/security.txt on every one of our names.

What we will not do

We will not scan a system whose owner has asked us not to. We will not use an address that cannot be identified as ours. We will not try to hide where a scan comes from: if an address of ours is blocked or listed, we retire it rather than move around the block.