CIPHER is a free, open-source platform that continuously inspects your Windows fleet against industry security frameworks—giving you real-time hardening scores, actionable findings, and audit-ready reports.
Free & open source · Apache 2.0 License · Self-hosted · No telemetry
Features
A lightweight agent and a powerful dashboard—no complex infrastructure required.
Agents report every 30 minutes. Your compliance posture is always current—not a point-in-time snapshot from last quarter's audit.
Pre-built profiles for Windows 10, 11, Server 2019 & 2022 check 50+ settings including Credential Guard, BitLocker, UAC, and SMB signing.
Define scan definitions in JSON, XML, or YAML. Include PowerShell scripts and dispatch them to individual agents, groups, or the entire fleet.
Get notified the moment an agent goes offline, AV is disabled, or compliance drops below your threshold. Push alerts to Slack, Teams, or any webhook endpoint.
Full visibility into every endpoint: OS version, IP, AV status, firewall state, and installed software. Search, filter, and export to CSV.
30-day score trend charts show whether your fleet is getting more secure over time. Track baseline scores and compliance scores side-by-side.
Organize endpoints into groups—Servers, Workstations, by office—and view per-group compliance breakdowns. Target scans and tasks by group.
Authenticate against Active Directory or manage local users. AD users are auto-provisioned on first login. Role-based access with Admin and Viewer roles.
Upload agent packages to the server and distribute them with a linking key. Agents self-register on first heartbeat—no manual enrollment required.
Open Source
CIPHER is released under the Apache 2.0 license. No vendor lock-in, no usage limits, no "enterprise tier" behind a paywall. You own your data and your deployment.
How It Works
No cloud dependencies, no SaaS subscriptions. Run CIPHER on your own server.
Run the ASP.NET Core server on any Windows or Linux machine. Uses SQLite by default—no external database to manage.
Deploy the lightweight Windows service to your endpoints. Point it at your server URL and linking key. Agents self-register on first heartbeat.
Open the dashboard and see your fleet's compliance posture instantly. Drill into per-agent findings, export CSV reports, and set up alerts.
Explore a fully populated dashboard with 15 agents, realistic compliance data, and 30 days of trend history. No sign-up required.
Demo credentials: admin / Admin123!
· Read-only — modifications are disabled.