Overview
CyberGuard helps property-management teams detect business email compromise (BEC), wire-fraud attempts, and malicious attachments. This policy describes what data we process during the pilot and how it is protected.
Data we collect
- Account information: email address, name, authentication metadata.
- Mailbox data (when you connect Outlook): message subject, sender, body text, and attachment metadata for messages you choose to sync and scan.
- Scan results: severity, threat indicators, and recommended actions generated by CyberGuard.
- Usage timestamps such as last login and last activity for security and retention.
How we use data
- Authenticate users and provide the threat-detection service.
- Scan email and files for BEC, phishing, and malware indicators.
- Display your private scan history and alerts within your account.
- Optional AI analysis: when you explicitly choose Scan with Claude, email subject and body (up to ~4k characters) are sent to Anthropic for analysis. Rules-only scanning does not use AI.
Subprocessors
We use third-party services to operate CyberGuard, including AWS (hosting), Microsoft (Outlook OAuth and mail read), and optionally Anthropic (opt-in AI scans). A full subprocessor list is available to customer security teams on request.
Security & retention
- OAuth mailbox tokens are encrypted at rest in production.
- Synced email bodies are encrypted at rest in production.
- Synced mail, scan events, and inactive accounts are purged after 30 days by default (configurable by your administrator).
- Public self-service registration is disabled during the pilot; access is invite-only.
Your controls
- Disconnect Outlook in Settings to stop mailbox sync.
- Use rules-only scanning by default; AI scans require an explicit action per message.
- Contact your administrator to deactivate your account.