CBC Cipher Removal & Security Headers Implementation

Scheduled Maintenance Report for Pipl product status

Completed

The scheduled maintenance has been completed.
Posted Oct 26, 2025 - 10:30 UTC

In progress

Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted Oct 26, 2025 - 09:30 UTC

Scheduled

Summary

As part of our ongoing security enhancement initiatives, we will be implementing the following security improvements to strengthen our web services and protect against known vulnerabilities:
1. Removal of weak CBC cipher suites to enhance encryption standards
2. Implementation of additional security headers to improve browser-level security

Changes Being Implemented

1. Cipher Suite Removal
The following weak CBC cipher suites will be disabled:
* TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
* TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

2. Security Headers Implementation
The following security headers will be added to enhance browser-level protection:
* HTTP Strict-Transport-Security (HSTS)
* Content-Security-Policy (CSP)
* Referrer-Policy
* X-Frame-Options
* X-Content-Type-Options
* Permissions-Policy

Recommended Actions
Update legacy clients to support modern cipher suites and Security headers


Expected Impact:
No downtime expected
Posted Sep 22, 2025 - 11:48 UTC
This scheduled maintenance affected: Pipl Trust API, Pipl Trust Insights, Pipl Search API, Pipl Search Insights, and Pipl Account Management.