Security & Trust
We hold your compliance data to the same standard we help you prove. Encrypted in transit and at rest, isolated per tenant, access-controlled on every request, and tested and hardened continuously.
Our Security Commitments
Encryption
Access Control
Infrastructure
Audit Logging
Data Privacy
Compliance
Microsoft 365 Integration Security
We understand M365 integration security is critical. Here's how we protect your Microsoft environment:
Microsoft OAuth 2.0
Authentication happens directly with Microsoft. We never see or store your credentials.
You Control Every Change
Nothing is deployed automatically. Every change is approved by a person and reversible in one click.
Least Privilege Access
We request only the minimum permissions, and scanning is read-only. We never access your emails, documents, or user data.
Revocable Anytime
You stay in control. Revoke our access anytime from Microsoft, with no data loss.
Secure Token Storage
Connection tokens are encrypted at rest and in transit, and never logged.
Admin Consent Required
Only a Global Administrator can authorise the connection, keeping it under your oversight.
Security Features
Common Security Questions
Can CYBERWHITE modify my Microsoft 365 environment?
Not without your explicit approval. Scanning only reads your configuration and never changes anything. The Microsoft 365 connection does include write permissions (Conditional Access and Intune) so AutoFix can remediate, but nothing is written to your environment until a consultant clicks Deploy on a specific fix. Every change is snapshotted, Conditional Access starts in report-only mode, and you can roll back in one click or revoke access anytime.
Who can see my assessment data?
Only authorized users in your organization. For MSPs, only assigned consultants can access client data. Data is never shared with third parties.
Where is my data stored?
Your data is hosted in Australia and stays onshore, encrypted at rest. Our AI inference runs in Australia too, so nothing leaves the country.
How do I disconnect M365 integration?
Revoke access anytime through Microsoft Entra ID Enterprise Applications or within CYBERWHITE settings. Historical assessment data remains until you delete it.
Is CYBERWHITE SOC 2 compliant?
CYBERWHITE is built with SOC 2 Type II controls in mind. Contact us for our current compliance status and documentation.
Built in Australia, hardened continuously
A compliance product has to hold itself to the standard it sells. We secure our own platform with layered, automated controls, and we recently completed a focused security-hardening programme.
Tested on every change
SAST and dependency scanning in CI
Continuously monitored
Runtime error and anomaly monitoring
Recently hardened
Authentication and access controls
Gateway-guarded data
No direct path to your data
Deny by default
Authorised on every request
Defence in depth
Layered request hardening
Australian Entity
ABN 31 598 198 475
DSI SMB1001
Licensed commercial holder
Data sovereignty
Data and AI inference stay in Australia