For procurement teams

Procurement pack. Honest about what's signed, what's pending.

CipherM is solo-founded and pre-Enterprise. We're honest about what's in place today vs in flight. Reach the founder at legal@cipherm.io to start a procurement conversation.

Download a redacted sample Audit Pack (PDF) →

Status today

Privacy policy
✅ shipped
Terms of service
✅ shipped
Security disclosure policy
✅ shipped
Status page + audit log
✅ shipped
Public CBOM registry (CycloneDX 1.6)
✅ live
GDPR — basic data deletion / export
✅ on request, see privacy policy
DPA (Data Processing Addendum)
📝 template available on request — email legal@cipherm.io
Subprocessor list
📝 maintained inline below
Security questionnaire (SIG / CAIQ)
📝 short form available on request
SOC 2 Type 1
🟡 in flight — Vanta-backed audit kicking off Q3 2026
SOC 2 Type 2
🟡 ~12 months after Type 1
ISO 27001
⏸️ deferred — re-evaluate after first Enterprise contract
HIPAA / BAA
⏸️ not applicable — CipherM scans code, not PHI
FedRAMP
⏸️ deferred — re-evaluate Year 3

Subprocessors

Third-party services that may receive customer data in the course of providing CipherM. Email privacy@cipherm.io to subscribe to change notifications.

Vercel
Marketing site hosting (US, EU)
Managed application host
Registry backend, database & CBOM artifact storage (US, automated backups). Provider confirmed before any customer data is processed.
Stripe
Subscription billing (when Pro tier ships)

Common questions

Where is data stored?

CBOM artifacts, metadata, and account data are stored on CipherM's managed application host (US region) with automated off-host backups. Vercel serves static marketing assets. Stripe holds billing data only when Pro is active. The subprocessor list above is updated before any customer data is processed.

Is data encrypted?

In transit: HTTPS/TLS everywhere. At rest: provider-managed disk encryption plus automated off-host backups. Application-level encryption for private CBOMs is on the roadmap.

Can we self-host?

Not yet for the registry. The OSS cipherm-scan CLI is fully self-hostable today (Apache-2.0). Self-hosted registry is a Year 2 Enterprise option.

Do you process PII?

Email addresses (waitlist, account login). Optional CBOM uploader account name. No PII in CBOM artifacts themselves — those contain only your code's cryptographic patterns.

How are incidents disclosed?

Per the security policy at /security: acknowledged within 72 hours, fix within 30/90 days, public credit on the changelog and security advisory.

What's your retention policy?

Server logs: 30 days. Public CBOMs: indefinite (deletable on request). Waitlist: until you ask us to forget you. Account data: until account deletion + 30-day grace.

Need a signed DPA or completed questionnaire?

Email legal@cipherm.io with your standard form attached. Reasonable turnarounds: DPA in 3 business days, SIG-Lite / CAIQ in 5.

Talk to founder →