Terms of Use — Cybersecurity and Technology Analysis
These terms cover the Cybersecurity and Technology Analysis tool at
discover.koinecyber.com, operated by Koine Cyber. They apply to the assessment
itself. Koine Cyber's general
terms of service
cover the wider relationship. Last updated 26 July 2026.
Who may run an assessment
You may only authorize a scan of an organization you administer and are permitted to have assessed. The tool checks that the account signing in holds the required administrator role, but that check confirms the account's permissions, not your authority to act for the business. Running an assessment against an organization you do not have permission to assess is a misuse of this tool.
What the assessment is
A one-time, read-only review of the security settings in a Microsoft 365 or Google Workspace account, scored against the CIS Foundations Benchmark, plus any answers you give in the discovery questions. It reads configuration only. It never reads the contents of mail, files or chats.
What it is not
- Not a penetration test. Nothing is attacked, exploited, or tested for weakness. Settings are read and compared against a public benchmark.
- Not a guarantee. A high score means the settings we could read looked good at the moment we read them. It does not mean you cannot be breached, and no score should be presented to an insurer, a customer or an auditor as proof that you are secure.
- Not complete. Anything we could not measure is marked as such rather than guessed at, and the report says how many checks that applied to. Some findings are rebuilt from change history, which can show what changed but cannot prove nothing else exists.
- Not a point-in-time certificate. The result describes one moment. A setting changed an hour later is not reflected in it.
- Not legal, insurance or compliance advice. A CIS reference in the report points at a public standard for context; it is not a statement that you meet any regulation.
Your report
The report is about your organization and it is yours. You may keep it, share it, and act on it however you choose. Koine Cyber also retains a copy in order to discuss the findings with you, and uses it to prepare recommendations. We do not sell it, and we do not share it with anyone outside Koine Cyber and the portfolio companies that operate this assessment on our behalf.
Reports are stored encrypted and are securely deleted on a retention schedule — 30 days by default. A small, non-sensitive record of the score and date is kept beyond that so a later assessment can show whether things improved. That record contains no findings and no account details. The privacy notice describes exactly what is read, stored and deleted.
Our access
Access is granted by you at Microsoft or Google, and the tool gives it up as soon as your report has been generated. Your report tells you whether that removal succeeded. You can also remove our access yourself at any time, before or after a scan, from your own administrator console — the report explains where.
Availability and cost
The assessment is offered free of charge and is provided as-is, with no guarantee of availability, and it may change or be withdrawn. Where Koine Cyber has provided an assessment at no charge, that does not create an entitlement to further assessments. Any engagement that follows is covered by its own agreement, not by these terms.
Liability
The assessment is provided as-is. Koine Cyber is not liable for any loss arising from a decision made on the basis of a report, from a finding the assessment did not detect, or from an interruption to the service. Nothing here limits liability that cannot be limited by law.
Questions
Anything about these terms, your report, or removing our access: ledmonds@ttscyber.com.
Cybersecurity and Technology Analysis