Playbook Download YAML

Cypho Scanning

Cypho runs an external attack-surface monitoring service. To do that, we regularly and gently probe the internet-facing systems that our customers ask us to keep watch over. This page describes that activity so anyone who notices it can understand where it comes from, confirm that it is us, and ask to be left out.

If a log or monitoring tool flagged connection attempts from one of our systems, the explanation is here.

Why your systems might see us

Every scan we run is tied to a specific organization that has engaged Cypho to watch its own external footprint. If our traffic reached you, the address or name we contacted sits inside an attack surface that one of our customers asked us to track. We look for exposed services and weak points so the organization that owns them can close the gap before someone hostile does. We do not sweep the internet at large, and any network can ask to be removed.

What a scan actually does

  • We knock on a short list of ports. Instead of probing everything, we try a small, fixed set of the ports where real services tend to live, just to learn which of them answer.
  • We identify what responds. Where a port replies, we take a light reading of the software behind it to record what it is and roughly which version.
  • We stay quiet. The traffic we direct at any single system is deliberately minimal — on the order of 0.01 Mbps, and capped well below 0.1 Mbps. At that volume a scan is a handful of small packets, not a flood: it places no meaningful load on your infrastructure and is meant to pass unnoticed.
  • We only look, never touch. Our scanner never signs in, never guesses credentials, never runs exploits, and never reads or copies data. It notes that a service is present; it does not make use of it.

Confirming the traffic is ours

There are two easy checks:

  • Reverse DNS. Look up the address the traffic came from. Ours resolve to names under [*.scan.cypho.io — placeholder], and those names point back to this page.
  • User agent. When our technology-fingerprinting step makes an HTTP request, it announces itself with the user agent [Cypho-Vigil/1.0 (+https://playbook.cypho.io/scanning/transparency) — placeholder].

You are welcome to filter our traffic on your own side; doing so changes nothing about the services you run. That said, the cleaner path is simply to ask us to stop, as described below.

Asking to be excluded

Email info@cypho.io with the subject "Scan exclusion request" and tell us:

  • The names, addresses, or ranges you want us to leave alone.
  • Enough detail for us to confirm you are entitled to speak for them.

Once a network is on our exclusion list, we skip it on every later scan before a single packet goes out. We aim to act on requests within [N business days — placeholder].

Reaching us

Send anything about our scanning to info@cypho.io. A clear subject line helps us route it quickly — for example:

  • "Scan exclusion request" to opt a network out.
  • "Scan abuse report" to raise a concern about our activity.

Cypho — [legal entity name and registered address — placeholder].