Data the sensor sends
The sensor sends one message type: a scan report. Nothing else. The structure below is the wire contract: a small JSON document, defined in a single file in the sensor repository (the report client) so this page can be checked against the code.
Per certificate
Section titled “Per certificate”| Field | Example | Notes |
|---|---|---|
| Certificates | ["MIIF…", …] |
The presented chain as one certificates array, base64-DER, leaf first - public data by definition |
| Observed IP | 10.20.4.10 |
Where it was found |
| Observed port | 443 |
|
| Observed hostname | www.example.com |
The configured name this probe came from. Empty for an address or CIDR target |
| Served SNI | www.example.com |
SNI sent during the handshake. Only a hostname target sends one |
| Protocol | PROTOCOL_HTTPS |
How it was reached |
| Timestamp | 2026-08-10T13:46:00Z |
When observed |
Per report
Section titled “Per report”Sensor identity, machine ID and the scan cycle’s start and end. The tenant is not in the payload - it comes from the mTLS client certificate, so a sensor cannot claim to belong to a different tenant, and the machine ID is checked against that same certificate rather than believed.
Alongside that, the report carries what automatic discovery decided:
| Field | Example | Notes |
|---|---|---|
| Networks scanned | ["10.0.5.0/24"] |
The host’s own networks it took on |
| Networks declined | [{"reason":"too_wide","count":2}] |
Counted per reason, not listed. A declined network is outside our limits, so its address is a third party’s |
| Networks it can see | fingerprint, network, interface name | One entry per network the host stands in, waiting to be confirmed or already confirmed. The fingerprint is an HMAC over the gateway’s hardware address and the network, keyed per tenant - it recognises the same network again and cannot be turned back into a MAC address |
The public address a report arrives from is not in the payload; it is what the connection came from, and it is kept alongside a network so that “same way out” can serve as confirmation. A network nobody decided about and nobody has seen for 30 days is deleted with its address.
What is never sent
Section titled “What is never sent”- Private keys. Not the sensor’s own, and not the scanned services’ - those it never has access to.
- Application data. No HTTP bodies, headers, mail contents or credentials.
- Host inventory beyond certificates. No process lists, no installed software, no user accounts, no file contents.
- Network topology. Only the addresses where a certificate was actually found, not a map of what else exists. The networks above are the ones this host itself stands in, so that you can decide what it may scan - not a survey of what is around it.
- Hardware addresses. The gateway’s MAC is read on your host to compute a fingerprint and is never transmitted. The fingerprint is one way.
Your internal addresses do leave
Section titled “Your internal addresses do leave”Be aware of what the first row of the table means: observed IPs and internal hostnames are transmitted and stored, because “which host serves this certificate” is the product’s core question. If a hostname is itself sensitive, exclude that range - an excluded target is never contacted and never reported.
Data location
Section titled “Data location”Reports land in the region your tenant is pinned to (eu or us) and stay
there. Regions do not replicate to each other.