For procurement and security review

Two products. Opposite answers. Never merged.

CipherM sells an offline desktop binary and runs a hosted CBOM registry. Their data models are opposites, so almost every question you are about to ask has two different correct answers. Every answer below is labelled with the product it applies to. If an answer is not labelled, treat it as unanswered and ask.

CipherM is Pierre Louis LLC, a Nevada limited liability company, and it is one person. That is disclosed here rather than discovered later, along with what mitigates it and what does not. Reach the founder at founder@cipherm.io.

Which one are you reviewing?

CipherM Desktop

A signed binary you run on your own hardware.

You download it, verify it, and run it inside your boundary. It reads the filesystem in front of it and writes its output beside it. CipherM operates no service in this product's data path and receives none of your data — not your source, not your findings, not your file names, not even the fact that you ran it.

Assessor $15,000 per seat · Enterprise $45,000 · Air-gapped $95,000+ · annual licence

CipherM Desktop
CipherM Registry

A hosted web application at cipherm.io.

The public CBOM registry, the CycloneDX validator, the free live-TLS scan, and accounts. It is an ordinary SaaS with ordinary SaaS consequences: what you upload is stored by CipherM, processed by CipherM's subprocessors, and reachable by legal process served on CipherM. Nothing on this page pretends otherwise.

Free tier · paid tiers on waitlist

Public registry

The questions, answered twice

Section references are to the CipherM Desktop Software Licence Agreement, published in full at /legal/desktop-licence.

Where does our data live?

CipherM Desktop

On your hardware, and nowhere else. The scanner reads the path you point it at and writes the CBOM and evidence pack to the path you name.

There is no CipherM copy to locate, because there is no mechanism that would produce one. This is the answer to the residency question too: your data is resident wherever you ran the binary.

CipherM Registry

In CipherM-controlled infrastructure. Registry records, accounts and the audit log are in a hosted libSQL (SQLite) database at Turso. Uploaded CBOM artifacts are in Vercel Blob with private access, served through the application so the visibility check lives in one place. The application itself runs on Vercel.

Provider regions are whatever those accounts are provisioned in. If data residency is a control for you, ask before you upload — do not infer a region from this page.

Can a subpoena served on CipherM reach our scan results?

CipherM Desktop

No, and not as a matter of policy. CipherM does not hold them and has built nothing capable of obtaining them, so there is nothing to compel and nothing to disclose by mistake.

This is a contractual commitment, not just an architectural one: Desktop Licence §3.2 states that CipherM receives no Customer or Customer-client data through the Software and therefore cannot disclose, lose, or be compelled to produce it.

CipherM Registry

Yes, for anything you uploaded. Public CBOMs are already public. Unlisted and private CBOMs are protected by an application access check, not by a key you hold, so CipherM can read them and can be made to produce them.

If that is unacceptable for a given codebase, that codebase belongs on Desktop, not here.

Who else is in the data path?

CipherM Desktop

Nobody. There is no subprocessor because there is no path — no upload endpoint, no licence server, no telemetry sink, no update check.

The delivery channel (a download, a USB transfer, whatever your environment permits) touches the binary on its way in. It never touches your results on the way out, because your results never leave.

CipherM Registry

Several, and they are listed in full below with what each one actually receives.

One deserves calling out here: an explicit AI action in the registry sends part of your CBOM — including up to 3,000 characters of the code snippet already recorded in it — to Anthropic. Nothing sends it on its own; it happens when someone presses the button.

Do you process personal data?

CipherM Desktop

Not through the product. There is no account, no registration, no activation and no licence phone-home, so the binary collects and transmits no personal data of any kind.

The personal data CipherM holds about a Desktop customer is contract administration: the names, email addresses and billing details on the Order Form, held in email and accounting records. That is normally outside the scope of a processor DPA because CipherM is not processing it on your behalf.

CipherM Registry

Yes. Sign-in gives CipherM the email address and display name from your identity provider (Google, GitHub, or your own OIDC/SSO). An uploader name is optional. Waitlist and contact submissions store the email and message you typed.

CBOM artifacts themselves carry your code's cryptographic patterns — rule matches, file paths, line numbers and short snippets — not personal data, unless you put personal data in a file path or a snippet.

What is your retention policy?

CipherM Desktop

There is no retention because there is no collection. Your evidence packs are deleted when you delete them.

One thing does persist by design: an Evidence Pack you have already produced. CipherM will take no step to invalidate, revoke, or retroactively watermark it (Licence §5.3), because a pack handed to a QSA in month three has to still be readable when the engagement is reviewed in month twenty.

CipherM Registry

Public CBOMs are kept indefinitely and deleted on request. Be precise about what that means: there is no self-serve delete button today. Deletion is manual, performed by the founder, on request to founder@cipherm.io.

Account records persist until account deletion. Request logs sit with the hosting provider under its retention default — CipherM runs no separate log store. The privacy policy is the controlling statement.

Is data encrypted?

CipherM Desktop

In transit: there is no transit. At rest: your disk, under whatever encryption you already apply to engagement material. Evidence packs are written as ordinary files to the path you name, and CipherM does not encrypt them for you — protect them the way you protect the rest of the engagement.

The rule bundle and the licence file are Ed25519-signed. That is integrity and authenticity, not confidentiality, and it should not be quoted as encryption.

CipherM Registry

In transit: HTTPS/TLS. At rest: provider-managed encryption on the database and the blob store.

CipherM adds no application-layer encryption. A private CBOM is private because of an access check, not because of a key you hold. Anyone with production access to the infrastructure can read it.

Can we self-host, or run this air-gapped?

CipherM Desktop

That is the entire product. It is designed to run on a machine that has never had a route to the internet: the licence is a signed file you install, rule updates are signed bundles you import from media, and the evidence pack is written locally.

Evaluation needs no licence key. An unlicensed install runs at full detection strength and writes complete evidence packs, so you can test the real binary on real code before any commercial conversation. Its output is watermarked UNLICENSED BUILD — NOT VALID AS EVIDENCE, and the manifest records the licence state — the licence changes whether output is admissible, not whether the tool works.

CipherM Registry

No. There is no self-hosted registry today and none is committed to a date. Anyone who tells you otherwise is quoting a roadmap, not a product.

The registry also carries no uptime SLA and no synthetic monitoring; the status page says so in its own words. It has been degraded and re-hosted before. Do not build a control that depends on its availability.

What happens if we stop paying?

CipherM Desktop

The software keeps running and keeps reporting every finding it reported during the Term. No licence state causes it to detect less, scan fewer files, or withhold artifacts (§3.4) — an assessor on an air-gapped network cannot renew a licence, and a tool that degrades there destroys the evidence chain it exists to produce.

CipherM cannot remotely disable, degrade or limit an installed copy, and has built no mechanism capable of doing so (§3.3). New packs produced after expiry carry the unlicensed watermark. Packs produced before it are untouched.

CipherM Registry

The free tier stays free. Paid registry tiers are on a waitlist and have no billing relationship to terminate yet.

Billing, when it exists, is Stripe. CipherM stores the Stripe customer and subscription identifiers, not card numbers.

Seat counts on Desktop are contractual, not technically enforced — enforcing them would require a licence server, which would require network calls. §4.3 replaces an audit right with a once-per-Term written self-certification and a true-up at list price, with no penalty and no retroactive charge.

The one claim worth checking

“No network calls” is the reason to buy this. So here it is stated precisely enough to disprove.

Desktop Licence §3.1 is headed Nothing is ever sent to CipherM, and that is the exact claim: no verb of this product ever connects to CipherM, for licensing, for rules, for telemetry, for updates, or for anything else. There is no such endpoint and no code that would call one.

That clause used to read “The Software makes no network connections”, full stop. It was rewritten on 2026-07-30 because the blanket version was not true: two verbs exist in order to connect, to hosts you name on the command line. A reviewer finds those in ten minutes, so they are the first thing listed here rather than the thing found later. User-directed connection to a target you chose is not phoning home — but the two are only distinguishable if someone says which is which, and a contract that overstates in its most load-bearing clause gets every other clause re-read in a worse light.

A · no outbound network code at all

scan · report · rules · licence · version · explain · fips · inventory · selfcheck. Everything that produces evidence is here. These verbs open no outbound socket, and the claim is enforced rather than asserted:

  • scan refuses a git URL outright. The ordinary CLI would clone one; the shipped binary answers “CipherM Desktop never fetches over the network — clone the repository yourself and scan the local path.”
  • Licence verification is Ed25519 against keys compiled into the binary. A test detonates socket.socket, create_connection, getaddrinfo and gethostbyname, then verifies a licence; any socket use fails the build.
  • Further tests read the source rather than trusting it. The licence module’s own AST is walked and the test fails if it imports socket, ssl, http, urllib, requests, ftplib, smtplib, asyncio, xmlrpc, webbrowser, telnetlib, poplib or imaplib. The rule-bundle module gets the same walk over a narrower list. Every file in the desktop package is separately scanned for references to urllib.request, http.client, socket.create_connection, requests, ssl.wrap_socket, ftplib, smtplib and telnetlib. Three different guards, listed separately because they cover different code.
  • The evidence pack cannot call out either. Its HTML is asserted to contain no script, iframe, link, form, src=, href=, fetch( or XMLHttpRequest, so opening it in a browser on a connected machine transmits nothing.
  • The frozen binary adds an egress guard around socket connect, connect_ex, sendto and create_connection for these verbs, raising rather than connecting to anything but loopback. Its honest scope, in the code’s own comment: defence in depth and a self-check, not a sandbox — it does not cover a C extension calling connect(2) or a subprocess. The guarantee is that the scan path contains no network code; the guard is what makes that testable instead of trusted.

B · connects, only to hosts you name

cipherm tls <host> and cipherm certs --endpoint <host>. Both ship in the binary. Both open outbound TLS connections. That is not a leak; it is the measurement.

  • tls completes a handshake with the host and port you typed and reports the negotiated protocol version, cipher, and key-exchange group, flagging classical groups as harvest-now-decrypt-later exposure. You cannot learn what a server actually negotiates without negotiating with it.
  • certs --endpoint fetches the leaf certificate from that endpoint to classify its public key. Given file paths instead, it reads PEM and DER off disk and connects to nothing.
  • The destination is always yours. Neither verb contacts CipherM, and neither transmits the result anywhere — it is printed or written to the file you asked for.
  • Skip them and the binary opens no outbound socket at all. If your change control forbids any egress from the assessment host, run only group A. No part of the evidence pack depends on group B.

C · one listener, loopback only

cipherm scan --serve opens a local dashboard so an assessor can read results without a terminal. It holds a customer’s findings in memory on a laptop, and is built accordingly:

  • Binds 127.0.0.1 and refuses any other address rather than trusting its caller.
  • Every route that returns scan data requires a per-run token compared with a constant-time check. Loopback is not an authorisation boundary: another local process, a browser extension, or another user on a shared workstation can all reach 127.0.0.1.
  • The Host header must name a loopback address, which closes DNS rebinding through the assessor’s own browser.
  • Strict CSP with no external origins, plus no-store, nosniff, no-referrer and frame-ancestors none. The page is a single self-contained file with no subresources — no CDN, no font fetch, no image fetch — so it renders identically air-gapped.

Check it without trusting this page

  • 1. Get the binary from /download. No licence key is needed to evaluate, and everything below can be done before any commercial conversation.
  • 2. cipherm version prints a network line, the rule bundle version and publish date, the signing key id, and whether the current configuration is evidence-grade.
  • 3. cipherm selfcheck re-hashes the rule bundle inside the binary against the build-time manifest and confirms Ed25519 verification works by rejecting a deliberately bad signature. It does not prove the binary was built from the published source, and does not claim to.
  • 4. Run a scan under your own egress monitoring. This is the only check on this list that requires trusting nothing on this page, and it is the one to do.

Compliance status, without the optimism

Nothing here is described as in flight, planned, or coming. A thing either exists and can be sent to you, or it does not exist. Where it does not, the second column says what is offered in its place, because “no, and here is what we do have” is a usable answer for a reviewer and silence is not.

SOC 2 Type 1

ABSENT

None. No auditor is engaged and no audit is scheduled.

An earlier version of this page said a Vanta-backed Type 1 was in flight for Q3 2026. Nothing had been started; the claim is withdrawn. What stands in its place for Desktop is that most of a SOC 2's operational surface does not exist in the product — no server, no account, no data egress — so a report would attest to the company, not the binary. For the binary itself, every release carries a CycloneDX 1.6 SBOM per executable, a SHA256SUMS file, and a detached Ed25519 signature over it, published ungated at /download ahead of the binary so a reviewer can read what is inside before asking anyone for permission to download. When no build is published, that page says so rather than showing digests nobody measured.

SOC 2 Type 2

ABSENT

None, and not scheduled. It cannot precede a Type 1.

If your policy requires a SOC 2 before any purchase, say so on the first call and the answer will be that CipherM does not clear that bar today.

Third-party penetration test

ABSENT

None commissioned. No report exists.

Desktop's remotely reachable attack surface is a loopback-only local dashboard, described in detail below; there is no server-side component to test. The registry's surface is in scope for the disclosure policy at /security, and good-faith research on it is invited there.

ISO 27001

ABSENT

None. Not started.

Re-evaluated after a first Enterprise contract, not before.

FedRAMP

N/A

Not applicable to Desktop, and absent for the registry.

FedRAMP authorises a cloud service. CipherM Desktop is software you run inside your own authorisation boundary — there is no CipherM service in its data path to authorise, which is the same reason it can run in an enclave at all. If your programme requires the tool itself to appear on an authorised list, raise it on the first call; the honest answer may be that CipherM is the wrong fit.

HIPAA / BAA

N/A

No BAA. None offered.

Desktop receives no data at all, so there is no PHI for CipherM to safeguard. For the registry, treat the absence of a BAA as a prohibition: do not upload anything containing PHI.

DPA (Data Processing Addendum)

ABSENT

No CipherM DPA template exists.

This page previously offered one on request; there was nothing to send. For Desktop there is normally nothing for a processor DPA to govern, because CipherM processes no customer personal data through the product — the only processing is contract administration, where CipherM is a controller of your commercial contact details. For the registry, send your standard DPA and it will be reviewed and negotiated. Expect redlines from a solo counterparty, not a countersignature by return.

Security questionnaire (SIG-Lite / CAIQ)

IN PLACE

A completed vendor security questionnaire response exists. Ask and it is sent.

It covers CipherM Desktop across the domains those forms use, so most rows can be answered by copying one. Every technical claim in it carries the command a reviewer can run to check it, and where a control is genuinely absent it says so rather than reaching for a euphemism. The 5-business-day turnaround this page used to publish was not measured against anything and has been removed: send your own form, and you will get a date for it in the reply rather than a number invented for a web page.

GDPR access, export and deletion

IN PLACE

Honoured on request, manually.

For Desktop there is nothing to export or delete, because nothing was collected. For the registry, email founder@cipherm.io; there is no self-serve tooling and the work is done by hand.

Desktop Licence Agreement

IN PLACE

Published in full, ahead of any conversation.

Read it at /legal/desktop-licence before the call rather than at signature. It has not been through outside counsel yet, so expect to redline it — the clauses that get negotiated are §8 (liability), §9 (indemnity) and §4.3, which replaces an audit right with a written self-certification because CipherM has no technical means of counting your seats.

Privacy policy · Terms · Security disclosure · Status

IN PLACE

Published.

Linked from the footer of every page. The security disclosure policy at /security states scope, response commitments, and what CipherM cannot offer a researcher.

Subprocessors

CipherM Desktop

None.

Not “none that matter” and not “none currently”. There is no third party in the data path because there is no data path: no upload endpoint, no licence server, no telemetry sink, no update check, no crash reporter. The list is empty for the same reason the retention policy is empty.

CipherM Registry

Third parties that receive data in the course of running cipherm.io. Each row below was read out of the code that calls it. Rows marked env-gated are inactive unless the corresponding credentials are configured on the deployment. Email founder@cipherm.io to be told before this list changes.

Vercel
Application hosting, CDN, and the page-view analytics loaded on every page of cipherm.io.
Turso
Hosted libSQL (SQLite). Registry records, accounts, the audit log, and waitlist/contact submissions.
Vercel Blob
Uploaded CBOM artifacts, stored private and served through the application's own access check.
Anthropic
Claude Haiku 4.5, on an explicit AI action only. Receives CBOM summary fields, and for a migration suggestion the rule id, file path, line number and up to 3,000 characters of the snippet already in your CBOM.
Google · GitHub · your OIDC provider
Sign-in only. CipherM receives the email address and display name your provider returns.
Google Fonts
Web fonts requested by the browser on every page load, which discloses the visitor IP to Google.
Stripe
Subscription billing when a paid registry tier is active. CipherM stores identifiers, never card numbers.
Resend
Lead-notification email to the founder when a form is submitted. Env-gated; inactive unless configured.
Upstash / Vercel KV
Anonymous scan counters. No scan content stored. Env-gated; inactive unless configured.
S3-compatible object store
Off-host backup of the registry database and artifacts. The provider is whichever bucket is configured (Cloudflare R2, AWS S3, MinIO), so no single policy can be linked here — ask which one is live before it matters to you. Env-gated; inactive unless configured.
n/a
Key person and continuity

One person. Said out loud, before you have to ask.

CipherM is Pierre Louis LLC, a Nevada limited liability company, and it is one person. The same person writes the code, holds the Ed25519 release signing key, answers the security inbox, and would sign your order form. There is no second engineer, no on-call rota, and no separation of duties between the developer and the release signer.

On an annual licence for a tool that produces compliance evidence, this is the first question any competent buyer asks, and it does not get better by being buried under a subprocessor table. What follows is the risk stated plainly, then the mitigations sorted by how much they are actually worth: what is already true and requires no promise, what is written into the contract, what is negotiable, and what does not exist.

What the risk actually is

  • Bus factor of one. If the founder is unavailable, no rule bundle is published and no support request is answered.
  • No 24/7 support, and no response-time SLA is published, because none has been measured. Support is one mailbox read by one person.
  • No separation of duties. The signing key lives in the macOS Keychain and never enters CI, which reduces key-compromise-via-CI risk but does not create separation of duties and should not be described as if it did.
  • No third-party audit, no penetration test, and no second reviewer of the detection rules your evidence depends on.
Structural

The tool does not stop working, and CipherM cannot make it stop.

No licence state causes Desktop to detect less, scan fewer files, or withhold artifacts (§3.4), and CipherM cannot disable, degrade or limit an installed copy because no mechanism capable of it was built (§3.3). If CipherM ceased to exist tomorrow, every installed copy would keep scanning at full strength on the last rule bundle it received. That is a consequence of the architecture, not a promise anyone has to keep.

Absent

But scanning is not the same as evidence, and that is the real clock.

Read the card above with this one or you will draw the wrong conclusion. An evidence pack built from a rule bundle more than 120 days old is stamped STALE — NOT VALID AS EVIDENCE (§6.2, and EVIDENCE_MAX_AGE_DAYS in the code). So if bundle publication stopped, the tool would keep scanning but would stop producing admissible evidence roughly four months later, for every customer at once. That — not the absence of new features — is the failure mode a continuity clause needs to cover, and it is why the refund right below is measured in days rather than left to good faith.

Structural

Evidence you have already produced stays valid.

CipherM will take no step to invalidate, revoke or retroactively watermark an Evidence Pack (§5.3). Your delivered work product does not depend on CipherM's continued existence, its licence server (there is none), or your renewal.

Structural

There is no hosted dependency in Desktop to lose.

No server to shut down, no account to deactivate, no API to deprecate. The failure mode that ends most single-founder SaaS tools — the service goes dark and the customer's data goes with it — has no equivalent here. The hosted registry is a different matter and is not something to build a control around.

Structural

Rule updates are data, not a new binary.

A rule bundle is a signed file you import. Staying current does not require a new build, a new signing ceremony, or a connection — which is also why a lapse in publishing degrades gracefully rather than breaking the tool.

Contractual

If updates stop for 90 days, you can leave with your money.

§5.5: if CipherM ceases to publish Rule Bundles for more than ninety consecutive days during the Term, you may terminate and take a pro-rata refund of the unused portion of the annual fee. The annual fee is substantially a subscription to signed rule updates; if those stop you have stopped receiving what you bought. This is the customer's remedy to exercise, not CipherM's discretion to grant, and it is the only continuity term in the standard agreement today.

Negotiable

Escrow is offered on request, and is not in place until you ask for it.

There is a written signing-key continuity procedure — encrypted backups in separated locations, verified on a schedule, with a named successor who has the material and the authority to use it — and CipherM will confirm the date of the most recent successful verification in writing on request, which is the only part of it you can actually audit. Source and key escrow with a mutually agreed agent is offered on Enterprise and Federal orders at your cost, releasable on defined triggers. None of that is engaged today: no escrow agent has been retained and no deposit has been made. Raise it before signature, because describing it as already in place would be the kind of false that surfaces at exactly the wrong moment.

Absent

There is still no second engineer.

Key continuity is not the same as engineering continuity. Nobody else can write a detection rule, judge a false negative, or answer a QSA's question about why a finding is what it is. There is no acquirer and no arrangement with anyone to take over maintenance. If your supplier standard requires a vendor that survives the loss of one person, CipherM does not meet it, and the right time to establish that is before a purchase order rather than after.

Send your paperwork.

Your DPA, your security questionnaire, your supplier form — email founder@cipherm.io with it attached and you will get a date for it in the reply rather than a turnaround time invented for a web page. If something on this page is wrong, that is the address to say so, and it will be corrected here.

Talk to the founder →