This page describes the supported content path, documented data-minimizing behavior, and controls that require validation against the deployed release and configuration.
BitDrip evaluates supported configured traffic in the customer-controlled path. Validated audit configurations can retain bounded metadata or hashes instead of full matched content; confirm logs, diagnostics, support flows, and retention for the deployed version.
PCI_CARD_NUMBER, GDPR_EMAIL). Human-readable, no content.
The supported AI-content evaluation path runs in customer-controlled components. The separate Anchor-operated portal handles the bounded commercial data categories described in the privacy notice.
The request is blocked before it reaches the AI provider. An audit event is created containing only: timestamp, rule name, violation category, content hash (SHA-256), user identity, and policy decision. The prompt text is discarded.
The request is forwarded to the AI provider over a fresh TLS connection. The provider receives the original request exactly as the user intended, with no modification.
BitDrip uses HTTPS interception to read encrypted AI traffic. This section explains the mechanism honestly, including what it means for your TLS trust model.
api.openai.com), signs it with the local CA key, and presents it to the browser. The browser sees a valid certificate because it trusts the CA. This is how BitDrip can read the encrypted request content.
Per-deployment CA generation and local key custody reduce cross-deployment exposure. They do not eliminate risk from privileged endpoint access, copied key material, trust-store changes, backups, or other administrative compromise. Validate the installed trust scope and key custody.
Installing a root CA in the OS trust store is a significant trust decision. Any process running with sufficient privileges on the same machine can potentially present certificates signed by that CA.
This is an inherent property of OS-level certificate trust, not a BitDrip-specific risk. Standard enterprise DLP products carry the same consideration.
The audit log supports tamper-evident verification where the documented hash chain is enabled and validated. Changes to covered chained entries can be detected when verification runs; this is not an immutability guarantee.
Chained events include the SHA-256 hash of the previous event. Deleting or modifying an event breaks subsequent verification, so the change is detectable when the documented chain verification runs.
Where the release and deployment evidence confirms per-event signing is enabled, signed events can be checked with the corresponding verification key. Validate the actual deployed audit schema and verifier before relying on this control.
Audit retention is controlled by the customer's self-hosted storage and compliance policy. Enterprise SIEM export can support customer-managed long-term preservation, but BitDrip does not promise tier-specific retention periods.
Four scenarios security architects regularly ask about — and the specific controls that address each one.
bitdrip ca rotate attempts to generate and install a new keypair and remove managed old trust entries. Administrators must verify every relevant physical OS and browser trust store after rotation; an old CA can remain trusted wherever cleanup did not complete.If you discover a security issue in BitDrip — the software, the portal, the documentation site, or any component we operate — please contact us at security@anchorcybersecurity.com.
We commit to responding within 48 hours with an acknowledgement and an initial assessment. For confirmed vulnerabilities, we will provide a remediation timeline within 7 days.
We credit researchers who follow coordinated disclosure — please allow us 90 days to patch before public disclosure. We will name you in the release notes unless you prefer to remain anonymous. We do not currently offer a monetary bug bounty, though we do offer recognition and reference letters for material findings.
We're happy to walk your security team through the architecture, answer questions about the CA model, or support a proof-of-concept deployment in your environment.