Skip to content

Data the sensor sends

The sensor sends one message type: a scan report. Nothing else. The structure below is the wire contract: a small JSON document, defined in a single file in the sensor repository (the report client) so this page can be checked against the code.

Field Example Notes
Certificates ["MIIF…", …] The presented chain as one certificates array, base64-DER, leaf first - public data by definition
Observed IP 10.20.4.10 Where it was found
Observed port 443
Observed hostname www.example.com The configured name this probe came from. Empty for an address or CIDR target
Served SNI www.example.com SNI sent during the handshake. Only a hostname target sends one
Protocol PROTOCOL_HTTPS How it was reached
Timestamp 2026-08-10T13:46:00Z When observed

Sensor identity, machine ID and the scan cycle’s start and end. The tenant is not in the payload - it comes from the mTLS client certificate, so a sensor cannot claim to belong to a different tenant, and the machine ID is checked against that same certificate rather than believed.

Alongside that, the report carries what automatic discovery decided:

Field Example Notes
Networks scanned ["10.0.5.0/24"] The host’s own networks it took on
Networks declined [{"reason":"too_wide","count":2}] Counted per reason, not listed. A declined network is outside our limits, so its address is a third party’s
Networks it can see fingerprint, network, interface name One entry per network the host stands in, waiting to be confirmed or already confirmed. The fingerprint is an HMAC over the gateway’s hardware address and the network, keyed per tenant - it recognises the same network again and cannot be turned back into a MAC address

The public address a report arrives from is not in the payload; it is what the connection came from, and it is kept alongside a network so that “same way out” can serve as confirmation. A network nobody decided about and nobody has seen for 30 days is deleted with its address.

  • Private keys. Not the sensor’s own, and not the scanned services’ - those it never has access to.
  • Application data. No HTTP bodies, headers, mail contents or credentials.
  • Host inventory beyond certificates. No process lists, no installed software, no user accounts, no file contents.
  • Network topology. Only the addresses where a certificate was actually found, not a map of what else exists. The networks above are the ones this host itself stands in, so that you can decide what it may scan - not a survey of what is around it.
  • Hardware addresses. The gateway’s MAC is read on your host to compute a fingerprint and is never transmitted. The fingerprint is one way.

Be aware of what the first row of the table means: observed IPs and internal hostnames are transmitted and stored, because “which host serves this certificate” is the product’s core question. If a hostname is itself sensitive, exclude that range - an excluded target is never contacted and never reported.

Reports land in the region your tenant is pinned to (eu or us) and stay there. Regions do not replicate to each other.