CybrOakSign in

Privacy Policy

Last updated: April 26, 2026

1. Who we are

ExanixSolutions LLC, doing business as CybrOak (“CybrOak,” “we,” “us”), provides an endpoint intelligence and visibility layer on top of Microsoft Intune. This Privacy Policy describes how we handle information about you and your organization when you use the service at cybroak.com.

2. What we collect

2.1 Account information

When you sign in with Microsoft, we receive from Microsoft Entra ID: your name, email address, Azure tenant ID, and your user object ID. We use these to authenticate you and scope your data to your organization.

2.2 Device telemetry from Microsoft Graph

With your explicit admin consent, we read managed-device metadata from your Microsoft Intune tenant via the Microsoft Graph API. This includes: device name, operating system, version, compliance state, BitLocker / Defender / firewall status, last sync time, enrolled user, manufacturer, model, and serial number. We do not read file contents, browsing history, location data, or any user-generated content from end-user devices.

2.3 Derived data

We compute and store: risk scores, findings, posture snapshots (daily), remediation history, audit log entries, and any device tags or custom rules you create.

2.4 Usage data

We collect minimal product analytics (page views, feature usage) to improve the service. We do not sell this data. We do not use third-party advertising trackers.

3. How we use your data

  • To operate the service (sync your fleet, detect findings, push remediations)
  • To send security alerts to webhooks (Slack/Teams) you configure
  • To send transactional email (sign-in confirmation, weekly digests if enabled)
  • To meet legal obligations and respond to audit requests from you

4. Data storage and security

Customer data is stored in encrypted PostgreSQL databases hosted on Railway in their US-East region. All traffic to and from CybrOak uses TLS 1.2 or higher. Microsoft refresh tokens are stored encrypted at rest. Backups run daily and are retained for 30 days.

Every database query is scoped by tenant_id. Two customers using CybrOak cannot view or access each other's data.

5. Subprocessors

The following third parties process your data on our behalf:

  • Vercel — frontend hosting and CDN
  • Railway — backend application and PostgreSQL database
  • Microsoft Graph API — the source of your device data
  • Resend — transactional email delivery (when enabled)
  • Stripe — payment processing (when applicable)
  • Sentry — application error tracking (no customer data; we mask all DOM content in error replays)

6. Data retention

We retain your data for the duration of your subscription. On cancellation, your data is retained for 30 days to allow reactivation, then permanently deleted. You can request immediate deletion at any time by emailing privacy@cybroak.com.

7. Your rights

Depending on your jurisdiction (GDPR, CCPA, UK DPA), you may have the right to access, correct, export, or delete your personal data. To exercise these rights, email privacy@cybroak.com.

8. Cookies

We use a single first-party cookie / localStorage entry (cybroak_token) to keep you signed in. We do not use third-party tracking or advertising cookies.

9. Changes to this policy

We'll notify customers of material changes by email at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.

10. Contact

Questions? privacy@cybroak.com

← Back to home·Privacy·Terms