Privacy Policy — Cybersecurity and Technology Analysis
This policy covers Koine Cyber's Cybersecurity and Technology Analysis tool at
discover.koinecyber.com. It describes exactly what the tool reads from a
Microsoft 365 or Google Workspace account, what is stored, for how long, and who sees it.
Last updated 21 July 2026.
What this tool does
Cybersecurity and Technology Analysis performs a one-time, read-only review of an organization's Microsoft 365 or Google Workspace configuration. An administrator authorizes it, it reads security settings, it produces a report scored against the CIS Foundations Benchmark, and it removes its own access. Nothing is installed, and nothing in the account is changed.
What we read
For Google Workspace we request the permissions below, plus the three standard sign-in permissions
(openid, email, profile) that tell us who authorized the scan.
We never ask for anything that reads the contents of mail, files or chats. If your account has already
granted this app other permissions in the past, Google may include those in the same sign-in; we only
ever use the ones listed here.
-
admin.directory.user.readonly— counts of accounts, whether they are active, when they last signed in, whether two-step verification is set up, and who holds admin roles. -
admin.directory.group.readonly— group counts, used to understand how access is organized. -
admin.directory.domain.readonly— the domains on the account, so we can check public email records (SPF, DKIM, DMARC) for each one. -
admin.directory.user.security— which third-party applications have been granted access to the account. This is how we find AI tools and other outside apps that can reach company data. -
admin.reports.audit.readonly— administrative activity, used only to tell whether anyone is actively managing the account and whether two-step verification is enforced.
What we never read
We do not request, and cannot access, the contents of email, files, documents, chats or calendars. We hold no scope that would permit it. We do not read Gmail or Google Drive content, and we do not send or modify anything.
What you tell us before the scan
Before choosing a platform you are asked for your name, work email address and, optionally, your company. We ask first rather than afterwards for one reason: if the scan does not finish — the wrong account was used, it turned out not to hold administrator rights, the permission list gave you pause — we would otherwise have no way to follow up or to help. That is the only reason it is collected.
It is used to send you your report and to contact you about this assessment. It is not added to a marketing list, not sold, and not shared outside Koine Cyber and the portfolio companies that operate this assessment. There is nothing to unsubscribe from. It is stored encrypted, deleted on the same 30-day schedule as the reports, and you can ask us to delete it sooner at any time — including if you never run a scan at all.
What is stored
The report stores aggregate figures and configuration settings, not records about individual people. For example, it stores "141 of 198 accounts have a second sign-in step set up", not the list of who they are. Where the scan checks each account's connected applications, the account address is used to make the request and is discarded; only the names of the applications found and the totals are kept.
Alongside the findings, a report holds:
- The organization's name and domains, as returned by Microsoft or Google.
- The names of third-party applications connected to the account.
- Answers to the discovery questionnaire, where someone chooses to complete it.
- The name, email address and phone number of anyone who asks us to send them the report.
- The name, email address and company given before the scan started, and which platform was chosen.
How it is stored and who can see it
Reports are encrypted at rest with AES-256-GCM on a server we control, and are reachable only through a long random link issued to the person who ran the scan. Access credentials obtained during a scan are held in memory for the length of the scan and are never written to disk. Traffic is encrypted in transit with HTTPS. Inside Koine Cyber, reports are visible to the staff working on the assessment.
How long it is kept
Reports are automatically and permanently deleted after 30 days, and so are the contact details given before a scan — including where no scan was ever run. You can ask us to delete either sooner, and we will do it on request.
How our access is removed
Our authorization is revoked as soon as the scan finishes. You can also remove it yourself at any time — for Google Workspace, under Admin console → Security → API controls → App access control; for Microsoft 365, under Entra ID → Enterprise applications.
Who else sees the data
We do not sell this data, we do not share it with advertisers, and we do not use it to train machine learning or AI models. It is used only to produce the assessment for the organization that requested it and to have the conversation that follows.
We use Mailgun to deliver the report by email, so a report sent by email passes through Mailgun's systems. Where an assessment leads to work with us, findings may be recorded in our internal service management system.
Google user data — Limited Use
The Cybersecurity and Technology Analysis tool's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your choices
Running a scan is voluntary and requires an administrator to authorize it. You can decline at the consent screen, revoke access afterwards, and ask us to delete your report at any time.
Contact
Questions about this policy, or requests to delete a report: sales@koinecyber.com.
Cybersecurity and Technology Analysis