Offline means no CLI egress
Running with --offline disables network enrichment and telemetry. The Preview build guide pairs it with --no-telemetry for an explicit, reviewable no-egress workflow.
CipherMap is designed for local analysis. This page separates the default local data flow, optional connected paths, and the exact maturity limits of the invitation-only Free developer source preview.
Local data flow
CipherMap reads the path you select. The Free developer-preview workflow does not require uploading a repository or creating a hosted project.
The CLI applies its embedded detection rules locally. Use --offline to disable optional network paths and --no-telemetry to suppress telemetry explicitly.
Terminal, JSON, and SARIF results are written locally at your direction. Paid evidence formats remain behind the separate Tier A commercial-build boundary.
Network boundary
“Local-first” does not mean every possible command is permanently disconnected. It means the core scan happens locally and connected behavior is a separate, operator-chosen path.
Running with --offline disables network enrichment and telemetry. The Preview build guide pairs it with --no-telemetry for an explicit, reviewable no-egress workflow.
Outside offline mode, supported enrichment or integration commands may contact the service you configure. Those paths are separate from local scanning and inherit the destination provider's handling rules.
Normal source-preview builds intentionally disable Tier A and Tier B licences. No account, hosted dashboard, or provider integration is needed for the Free local workflow.
Release maturity
CipherMap publishes the boundary of what has been exercised instead of treating a successful compile as production qualification.
Read the Preview build boundaryTo report a suspected CipherMap security issue privately, email security@ciphermap.io with a minimal reproduction and avoid including third-party source code or secrets.