Privacy Policy
Last updated: June 28, 2026
FocusIntel (“FocusIntel,” a CyberIQ Experience, “we,” “us,” or “our”) is a compliance-evidence platform operated by CyberIQ that helps organizations assess and demonstrate their CMMC and NIST SP 800-171 posture. This Privacy Policy explains what information we collect, how we use and protect it, and the choices you have. It applies to cmmc.cyberiq.com and the FocusIntel service (the “Service”).
Information we collect
- Account information. When you sign in, we receive your name, email address, and organization from your identity provider (Google or Microsoft) through AWS Cognito. We use this to authenticate you and associate you with your organization’s account.
- Compliance evidence from connected sources. When an administrator connects a Google Workspace or Microsoft 365 tenant, we collect only the audit-log events and security-configuration data needed to evaluate compliance controls (for example, sign-in and admin activity logs, multi-factor-authentication and conditional-access settings, and directory role assignments). We do not collect the contents of your emails, files, or messages.
- Service and log data. We collect operational logs and metrics (such as request timestamps and error events) needed to run, secure, and troubleshoot the Service.
How we use information
- To authenticate users and operate the Service.
- To generate compliance posture, evidence, scoring, and reports (such as SSP and POA&M documents) for your organization.
- To secure, maintain, monitor, and improve the Service.
- To comply with legal obligations and enforce our agreements.
We do not sell your information, and we do not use the data we collect from connected sources for advertising.
Google user data and Limited Use
FocusIntel’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the read-only scopes needed to assess compliance, use that data solely to provide and improve the compliance features you enable, do not transfer it except as necessary to provide the Service or to comply with law, and do not use it for advertising or sell it. Information obtained from Microsoft 365 / Microsoft Graph is handled on the same basis.
How we share information
We share information only with service providers that host and operate the Service on our behalf (for example, Amazon Web Services for cloud infrastructure), bound by confidentiality and data-protection obligations; with your organization’s own administrators; and where required by law or to protect rights and safety.
Data retention
We retain compliance evidence for the period your organization configures for its evidence-retention obligations, and account data for as long as your account is active. On verified request, we delete or de-identify data when it is no longer needed, subject to legal and contractual retention requirements.
Security
We protect information using encryption in transit and at rest, least-privilege access controls, network isolation, and audit logging. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.
Your choices and rights
An administrator can disconnect a source at any time, which stops further collection from that source. Depending on your location, you may have rights to access, correct, or delete personal information. To make a request, contact us using the details below; we may need to verify your identity and route the request through your organization’s administrator.
Children’s privacy
The Service is intended for use by organizations and is not directed to children under 13, and we do not knowingly collect information from them.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice.
Contact us
If you have questions about this Privacy Policy or our data practices, contact us at support@cyberiq.com.