Koine Cyber Cybersecurity and Technology Analysis
Privacy Policy

Privacy Policy — Cybersecurity and Technology Analysis

This policy covers Koine Cyber's Cybersecurity and Technology Analysis tool at discover.koinecyber.com. It describes exactly what the tool reads from a Microsoft 365 or Google Workspace account, what is stored, for how long, and who sees it. Last updated 21 July 2026.

What this tool does

Cybersecurity and Technology Analysis performs a one-time, read-only review of an organization's Microsoft 365 or Google Workspace configuration. An administrator authorizes it, it reads security settings, it produces a report scored against the CIS Foundations Benchmark, and it removes its own access. Nothing is installed, and nothing in the account is changed.

What we read

For Google Workspace we request the permissions below, plus the three standard sign-in permissions (openid, email, profile) that tell us who authorized the scan. We never ask for anything that reads the contents of mail, files or chats. If your account has already granted this app other permissions in the past, Google may include those in the same sign-in; we only ever use the ones listed here.

What we never read

We do not request, and cannot access, the contents of email, files, documents, chats or calendars. We hold no scope that would permit it. We do not read Gmail or Google Drive content, and we do not send or modify anything.

What you tell us before the scan

Before choosing a platform you are asked for your name, work email address and, optionally, your company. We ask first rather than afterwards for one reason: if the scan does not finish — the wrong account was used, it turned out not to hold administrator rights, the permission list gave you pause — we would otherwise have no way to follow up or to help. That is the only reason it is collected.

It is used to send you your report and to contact you about this assessment. It is not added to a marketing list, not sold, and not shared outside Koine Cyber and the portfolio companies that operate this assessment. There is nothing to unsubscribe from. It is stored encrypted, deleted on the same 30-day schedule as the reports, and you can ask us to delete it sooner at any time — including if you never run a scan at all.

What is stored

The report stores aggregate figures and configuration settings, not records about individual people. For example, it stores "141 of 198 accounts have a second sign-in step set up", not the list of who they are. Where the scan checks each account's connected applications, the account address is used to make the request and is discarded; only the names of the applications found and the totals are kept.

Alongside the findings, a report holds:

How it is stored and who can see it

Reports are encrypted at rest with AES-256-GCM on a server we control, and are reachable only through a long random link issued to the person who ran the scan. Access credentials obtained during a scan are held in memory for the length of the scan and are never written to disk. Traffic is encrypted in transit with HTTPS. Inside Koine Cyber, reports are visible to the staff working on the assessment.

How long it is kept

Reports are automatically and permanently deleted after 30 days, and so are the contact details given before a scan — including where no scan was ever run. You can ask us to delete either sooner, and we will do it on request.

How our access is removed

Our authorization is revoked as soon as the scan finishes. You can also remove it yourself at any time — for Google Workspace, under Admin console → Security → API controls → App access control; for Microsoft 365, under Entra ID → Enterprise applications.

Who else sees the data

We do not sell this data, we do not share it with advertisers, and we do not use it to train machine learning or AI models. It is used only to produce the assessment for the organization that requested it and to have the conversation that follows.

We use Mailgun to deliver the report by email, so a report sent by email passes through Mailgun's systems. Where an assessment leads to work with us, findings may be recorded in our internal service management system.

Google user data — Limited Use

The Cybersecurity and Technology Analysis tool's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Your choices

Running a scan is voluntary and requires an administrator to authorize it. You can decline at the consent screen, revoke access afterwards, and ask us to delete your report at any time.

Contact

Questions about this policy, or requests to delete a report: sales@koinecyber.com.

← Back to Cybersecurity and Technology Analysis