Security and data flow
What CYNC reads, what it writes, where it runs, and which connections it makes. This page describes what the software does today. Items that are not confirmed yet are marked as such.

Data flow
CYNC runs on a Windows machine you control. Users go from Entra ID to mailbox contact folders through Microsoft Graph.
Microsoft Entra ID
Your tenant: users and groups
CYNC service
Windows machine you run
Exchange Online
Your tenant: contact folders
The service reads users and groups from your tenant and writes contacts into the mailboxes you choose. Contacts are matched with the com.itbaer.cync Open Extension. Contacts without it are treated as orphans and are never touched.
Permissions
CYNC uses application permissions on an app registration in your tenant.
| Microsoft Graph permission | Used for |
|---|---|
| User.Read.All | Read users from Entra ID (the source of the contacts). |
| Group.Read.All | Read group membership, for group-based sources and targets. |
| Contacts.ReadWrite | Create, update and delete contacts in the contact folder of each target mailbox. |
The service signs in with a certificate, not a password or client secret. You generate the certificate in the CYNC app and upload its public part to the app registration. Setup steps are in the Entra ID setup guide.
Network connections
These are the destinations the CYNC service connects to, taken from its source code.
| Destination | Purpose | When |
|---|---|---|
| graph.microsoft.com | Read users and groups, write contacts, in your own tenant. | Every sync run. |
| license.cync365.com | License activation and verification, and the free-tier heartbeat. Details below. | On activation. Licensed installs check in every 24 hours; if the server is unreachable for 7 days, the license is disabled. Free tier at most once every 24 hours. |
| cync365.com/api/version | Check whether a newer CYNC version exists. | When the update check runs. |
| Teams or Slack webhook, api.telegram.org | Notifications, only if you configure a notification channel. | On the events you select. |
What the activation server receives
Directory data and contact data are not part of these requests.
- Licensed installations
- License ID, machine fingerprint and a hash of the license key. The server keeps one machine per license and rejects a second machine.
- Free tier (up to 10 users)
- A SHA-256 hash of your tenant ID, the machine fingerprint and the number of enabled target users. This lets the server keep the 10-user free tier from being stacked across installations in one tenant.
- Analytics and telemetry
- The service source contains no analytics or crash-reporting code.
Where it runs
On your hardware, under your access controls.
- The sync engine is a Windows service. The admin app is a separate WinUI 3 program that talks to the service.
- Remote administration of a Server Core machine is optional and uses TLS only. There is no plain HTTP fallback.
- License keys are RSA-2048 signed and checked locally against a public key built into the service.
This website and purchases
Payments and license delivery use these processors.
Stripe processes payments, Cloudflare provides hosting, CDN and the activation service, and Google delivers license emails. IT-BAER does not store card details. The privacy policy lists the data each processor handles.
Not yet confirmed
Open items, listed so that nothing is implied that has not been checked.
| Installer code signing | Not yet confirmed. IT-BAER will state here whether the MSI and Setup.exe are signed. |
|---|---|
| Vulnerability reporting process | Not yet confirmed. Until then, report security issues to [email protected]. |