Kyvoi is a Microsoft 365 security assessment service. This policy explains what we access when we scan your tenant, what we store, and the rights you have over your information.
The short version: Kyvoi connects to your Microsoft 365 tenant with read-only permissions through Microsoft's official OAuth 2.0 consent. We read security configuration to produce your report — we do not modify anything in your tenant, and we do not retain your tenant's data after the scan.
1. Who we are
This service is operated by Kyvoi Ventures Private Limited ("Kyvoi", "we", "us"), a company registered in India. For any privacy question you can reach us at support@kyvoi.com.
2. What we access in your tenant
When an administrator connects a Microsoft 365 tenant, Kyvoi requests read-only Microsoft Graph permissions. We use this access solely to read security-relevant configuration — identity and conditional access policies, admin role assignments, device compliance settings, audit-logging configuration and similar controls. Kyvoi never requests write permissions and cannot change your configuration.
3. What we do not store
Your tenant's configuration is read in real time to generate your report. We do not build a standing copy of your tenant data. Access tokens issued during consent are held only as long as needed to complete the scan and are stored encrypted; you can revoke Kyvoi's access at any time from your Microsoft Entra admin center. We never see or receive your users' passwords.
4. Information we do collect
- Account & contact details — name, work email and company, provided when you register, request a report, or purchase a plan.
- Order & billing information — plan, transaction identifiers and, where you purchase through Microsoft commercial marketplace, the associated marketplace order details.
- Report metadata — the scores and findings generated for your tenant, retained so you can access your reports and track posture over time.
- Basic usage & log data — standard technical logs used to operate and secure the service.
5. How we use your information
We use it to run scans and deliver reports, provide AI advisory and remediation guidance, manage your account and billing, respond to support requests, and keep the service secure. We do not sell your personal information.
6. Sub-processors
We rely on a small number of trusted providers to run Kyvoi: Microsoft Azure (hosting, database and secret management) and Anthropic (the AI model that powers report advisory). These providers process data only to provide their service to us and under their own security and privacy commitments.
7. Data retention
We keep account, order and report information for as long as your account is active or as needed to provide the service and meet legal obligations. You may request deletion of your account and associated reports at any time.
8. Security
Kyvoi runs on Azure with managed-identity secret handling, encryption of sensitive values, and least-privilege, read-only tenant access. Given the nature of our product, security is central to how we build and operate.
9. Your rights
Depending on your location, you may have rights to access, correct, export or delete your personal information, and to withdraw consent. We handle personal data in line with India's Digital Personal Data Protection Act, 2023, and, where applicable, the EU GDPR. To exercise any right, contact us at support@kyvoi.com.
10. Changes to this policy
We may update this policy from time to time; the "last updated" date above reflects the current version. Material changes will be communicated through the service.
11. Contact
Questions about this policy or your data? Email support@kyvoi.com.
