Security & Trust

We hold your compliance data to the same standard we help you prove. Encrypted in transit and at rest, isolated per tenant, access-controlled on every request, and tested and hardened continuously.

Our Security Commitments

Encryption

TLS 1.3 in transit, AES-256 at rest

Access Control

Role-based access control with secure authentication

Infrastructure

AWS Sydney (Australia) enterprise cloud hosting

Audit Logging

Every API call + change logged with timestamp, actor and tenant ID

Data Privacy

Your data stays yours, not sold to third parties

Compliance

Built with SOC 2 Type II controls in mind

Microsoft 365 Integration Security

We understand M365 integration security is critical. Here's how we protect your Microsoft environment:

Microsoft OAuth 2.0

Authentication happens directly with Microsoft. We never see or store your credentials.

You Control Every Change

Nothing is deployed automatically. Every change is approved by a person and reversible in one click.

Least Privilege Access

We request only the minimum permissions, and scanning is read-only. We never access your emails, documents, or user data.

Revocable Anytime

You stay in control. Revoke our access anytime from Microsoft, with no data loss.

Secure Token Storage

Connection tokens are encrypted at rest and in transit, and never logged.

Admin Consent Required

Only a Global Administrator can authorise the connection, keeping it under your oversight.

Security Features

Encryption at Rest and Transit: AES-256 encryption at rest, TLS 1.3 for all data in transit
Audit Logging: Activity logs for authentication, data access, and system changes. Events relevant to ISO 27001 and SOC 2 controls are tagged at write time for downstream audit reporting.
Multi-Tenant Data Isolation: Tenant data isolation ensures your data never mixes with other organizations
Daily Automated Backups: Daily encrypted backups with 7-day retention and point-in-time recovery
OAuth Security: Microsoft 365 integration uses OAuth 2.0 with least-privilege scopes. Write permissions are requested at connect but never exercised until a consultant clicks deploy on a specific AutoFix recommendation.
Secure Development Pipeline: Every change passes automated security testing (static analysis and dependency scanning) and review before it ships
Continuous Security Review: We regularly audit our own platform's access controls, including multi-tenant isolation, and remediate findings fast.
Audit Log Retention: Tiered retention policies (standard, extended, permanent) for security and compliance audit trails. Customer data deletion available on written request.
Australian Data Sovereignty: All data hosted in AWS Sydney with compliance to Australian privacy laws

Common Security Questions

Can CYBERWHITE modify my Microsoft 365 environment?

Not without your explicit approval. Scanning only reads your configuration and never changes anything. The Microsoft 365 connection does include write permissions (Conditional Access and Intune) so AutoFix can remediate, but nothing is written to your environment until a consultant clicks Deploy on a specific fix. Every change is snapshotted, Conditional Access starts in report-only mode, and you can roll back in one click or revoke access anytime.

Who can see my assessment data?

Only authorized users in your organization. For MSPs, only assigned consultants can access client data. Data is never shared with third parties.

Where is my data stored?

Your data is hosted in Australia and stays onshore, encrypted at rest. Our AI inference runs in Australia too, so nothing leaves the country.

How do I disconnect M365 integration?

Revoke access anytime through Microsoft Entra ID Enterprise Applications or within CYBERWHITE settings. Historical assessment data remains until you delete it.

Is CYBERWHITE SOC 2 compliant?

CYBERWHITE is built with SOC 2 Type II controls in mind. Contact us for our current compliance status and documentation.

Built in Australia, hardened continuously

A compliance product has to hold itself to the standard it sells. We secure our own platform with layered, automated controls, and we recently completed a focused security-hardening programme.

Tested on every change

SAST and dependency scanning in CI

Continuously monitored

Runtime error and anomaly monitoring

Recently hardened

Authentication and access controls

Gateway-guarded data

No direct path to your data

Deny by default

Authorised on every request

Defence in depth

Layered request hardening

Australian Entity

ABN 31 598 198 475

DSI SMB1001

Licensed commercial holder

Data sovereignty

Data and AI inference stay in Australia

Questions About Security?

Contact our security team for detailed documentation, compliance reports, or custom security requirements