Security and data flow

What CYNC reads, what it writes, where it runs, and which connections it makes. This page describes what the software does today. Items that are not confirmed yet are marked as such.

Data flow

CYNC runs on a Windows machine you control. Users go from Entra ID to mailbox contact folders through Microsoft Graph.

Microsoft Entra ID

Your tenant: users and groups

Graph API

CYNC service

Windows machine you run

Graph API

Exchange Online

Your tenant: contact folders

The service reads users and groups from your tenant and writes contacts into the mailboxes you choose. Contacts are matched with the com.itbaer.cync Open Extension. Contacts without it are treated as orphans and are never touched.

Permissions

CYNC uses application permissions on an app registration in your tenant.

Microsoft Graph permissionUsed for
User.Read.AllRead users from Entra ID (the source of the contacts).
Group.Read.AllRead group membership, for group-based sources and targets.
Contacts.ReadWriteCreate, update and delete contacts in the contact folder of each target mailbox.

The service signs in with a certificate, not a password or client secret. You generate the certificate in the CYNC app and upload its public part to the app registration. Setup steps are in the Entra ID setup guide.

Network connections

These are the destinations the CYNC service connects to, taken from its source code.

DestinationPurposeWhen
graph.microsoft.comRead users and groups, write contacts, in your own tenant.Every sync run.
license.cync365.comLicense activation and verification, and the free-tier heartbeat. Details below.On activation. Licensed installs check in every 24 hours; if the server is unreachable for 7 days, the license is disabled. Free tier at most once every 24 hours.
cync365.com/api/versionCheck whether a newer CYNC version exists.When the update check runs.
Teams or Slack webhook, api.telegram.orgNotifications, only if you configure a notification channel.On the events you select.

What the activation server receives

Directory data and contact data are not part of these requests.

Licensed installations
License ID, machine fingerprint and a hash of the license key. The server keeps one machine per license and rejects a second machine.
Free tier (up to 10 users)
A SHA-256 hash of your tenant ID, the machine fingerprint and the number of enabled target users. This lets the server keep the 10-user free tier from being stacked across installations in one tenant.
Analytics and telemetry
The service source contains no analytics or crash-reporting code.

Where it runs

On your hardware, under your access controls.

  • The sync engine is a Windows service. The admin app is a separate WinUI 3 program that talks to the service.
  • Remote administration of a Server Core machine is optional and uses TLS only. There is no plain HTTP fallback.
  • License keys are RSA-2048 signed and checked locally against a public key built into the service.

This website and purchases

Payments and license delivery use these processors.

Stripe processes payments, Cloudflare provides hosting, CDN and the activation service, and Google delivers license emails. IT-BAER does not store card details. The privacy policy lists the data each processor handles.

Not yet confirmed

Open items, listed so that nothing is implied that has not been checked.

Installer code signingNot yet confirmed. IT-BAER will state here whether the MSI and Setup.exe are signed.
Vulnerability reporting processNot yet confirmed. Until then, report security issues to [email protected].