Trust

How CyberProva protects your data

We are asking you to connect a security tool to your Microsoft 365 tenant. You should expect a straight answer about what that means before you do.

What access we ask for, and what we do with it

CyberProva reads. It has no permission to change anything in your Microsoft 365 tenant, and does not request Global Administrator as an API permission. An administrator in your organisation grants consent through Microsoft's own admin consent screen, and can withdraw it at any time from the Microsoft 365 admin centre without contacting us.

The specific permissions are listed in our documentation rather than summarised, so you can check each one against Microsoft's description. Every automated result is stored with the check it relates to, the time it ran and the finding, so you can see exactly what was looked at.

Where a permission has not been granted, the affected check reports that plainly. It never guesses, and it never records a pass it could not establish.

Where your data lives

  • Hosted on Microsoft Azure. Application, database and file storage run in one region, with data at rest encrypted by the platform.
  • Evidence files are held in private storage. There is no public access, and downloads are authenticated and scoped to your organisation.
  • Traffic is encrypted in transit with TLS 1.2 or better. The application is served over HTTPS only, with HSTS.
  • Secrets — API credentials and keys — are held in a managed secret store, not in configuration files or source control.
  • Database access uses a managed identity over a private network path rather than a shared password.

Separation between organisations

Every record carries the organisation it belongs to, and every query is filtered by it. Access is controlled by role — owner, reviewer or member — and enforced on the server for every action, not just hidden in the interface. Cross-organisation access is covered by automated tests that run on every change.

What we deliberately do not collect

Our leaked-credential check reads Microsoft's own detections for your tenant. It requests the affected accounts by directory identifier and never asks Microsoft for the email addresses , because a stored list of employees whose credentials have appeared in a breach is sensitive personal data we have no need to hold.

We do not crawl the dark web, and we do not describe our checks as doing so. What we report is what Microsoft has observed for your tenant.

What we are honest about

A security product should be clear about its limits, so these are ours:

  • CyberProva is not a certification body . Our assessment is not a Cyber Essentials certificate or any other formal certification.
  • Most controls are established from evidence supplied by you, your IT team or your IT provider. We record and structure that evidence; we do not independently verify the underlying facts.
  • Assessments are periodic, not real time. Between runs, a configuration can change without us seeing it.
  • No assessment can establish that an organisation has not already been compromised.

Reporting a vulnerability

If you believe you have found a security issue in CyberProva, please tell us before disclosing it publicly. We will acknowledge your report and keep you updated while we investigate.

security@cyberprova.com