Trust & Security

Industry-Leading Security and Privacy Practices

PrivacyHawk's security controls are independently audited under SOC 2 Type II. PrivacyHawk Enterprise has passed the Google Workspace Marketplace and Microsoft Marketplace security reviews, and every release of the PrivacyHawk app is reviewed by Apple and Google Play.

Trusted & Compliant
AICPA SOC 2 compliantCCPA / CPRA compliant — California Privacy Protection AgencyGDPR compliantBBB A+ Accredited Business
At a Glance

Security and Privacy Commitments

✓

SOC 2 Type II Audited

Security, Confidentiality, and Privacy criteria. No exceptions noted by the independent auditor.

✓

Message Metadata Only

Enterprise scans read sender domains from message metadata. Message bodies, attachments, and subject lines are never retrieved.

✓

No Sale of Data

PrivacyHawk does not sell personal or organizational data.

✓

Encrypted at Rest and in Transit

AES-256 at rest, with keys managed and rotated in Google Cloud KMS. TLS 1.2 or higher in transit.

✓

Immediate Data Deletion

Revoke access, cancel, or request deletion, and tenant data, everything derived from it, and related logs are deleted immediately, and backups within 7 days.

✓

Access Revocable by Your Admins

Admins can disconnect PrivacyHawk at any time from the Google Admin console or the Microsoft 365 admin center.

Independent Verification

Certified by Industry-Leading Auditors

The independent audits and platform security reviews PrivacyHawk has completed.

SOC 2 Type II

Reviewed By: Percilchofe CPA LLC, an independent CPA firm

  • Security, Confidentiality, and Privacy criteria
  • Covers the PrivacyHawk app and PrivacyHawk Enterprise
  • No exceptions noted

Audited annually. Report available upon request.

Contact the Account Team →

Google Workspace Marketplace

Reviewed By: Google Trust & Safety and a Google-authorized security lab

  • OAuth app verification of requested permissions and their use
  • CASA Tier 2 security assessment against the OWASP Application Security Verification Standard

CASA is renewed annually.

Coming Soon

Microsoft Marketplace

Reviewed By: Microsoft

  • Publisher verification, shown by the verified badge on the Microsoft Entra consent screen
  • Microsoft Marketplace certification of the listing and offer

Member of the Microsoft AI Cloud Partner Program.

View on Microsoft Marketplace →

Apple App Store and Google Play

Reviewed By: Apple App Review and Google Play review

  • Every release reviewed against each store's privacy and data-use policies

Every release, before it reaches users.

Download on the App StoreGet it on Google Play
✓
Quarterly Independent Penetration Test
✓
Weekly Vulnerability Scans
✓
A+ RiskRecon Security Rating
For IT and Security Teams

Permissions, Data Retrieved, and Data Stored

Google and Microsoft permissions grant access to more fields than PrivacyHawk uses. This is what each permission allows, what PrivacyHawk retrieves, and what it stores.

Google Workspace

Permission Allows
gmail.metadata
Sender address
Recipients
Subject line
Date
Labels
Thread and message IDs
History
Message bodies and attachments are not included in this permission.
↓
PrivacyHawk Retrieves
Sender domain
Message date
↓
PrivacyHawk Stores
Third-party domain
First seen date
Last seen date

Directory permission admin.directory.user.readonly is used only to list licensed accounts. Drive, Calendar, Contacts, Chat, and Meet are not requested.

Microsoft 365

Permission Allows
Mail.ReadBasic.All
Sender address
Recipients
Subject line
Date
Other basic properties
Message bodies, previews, and attachments are not included in this permission.
↓
PrivacyHawk Retrieves
Sender domain
Message date
↓
PrivacyHawk Stores
Third-party domain
First seen date
Last seen date

Directory permission User.Read.All is used only to list licensed accounts.

Never Retrieved or Stored

✕
Message bodies
✕
Recipient lists
✕
Attachments
✕
Individual sender addresses
✕
Subject lines
✕
Calendar or file contents

Visible to Administrators

✓
Third-party companies and services found across the tenant
✓
Dates observed, plus exposure and risk scores

Administrators cannot see messages, subject lines, individual senders, or anything in an employee's personal PrivacyHawk account.

For App Users

Transparency, Control, and Protection of Your Data

What We Don't Do

✕
Sell personal data
✕
Share personal data for cross-context behavioral advertising
✕
Use Google account data for advertising, credit decisions, or lending

How We Handle Your Data

✓
Email scans identify companies by sender domain. Full emails are read only when they relate to your opt-out requests or are flagged as scams.
✓
Opt-out requests are sent from your own mailbox with only your name and email address.
✓
Identifiers added for dark web monitoring, such as an SSN, are stored encrypted using Google Kubernetes Engine (GKE) encryption.
✓
Disconnect email access or delete your account in the app at any time.
Privacy Policy →
Documentation

Security Documentation

The following documents are available upon request from the PrivacyHawk account team.

Security Overview
Architecture, control domains, and verification schedule
Available upon request
SOC 2 Type II Report
Available upon request
Penetration Test Executive Summary
Available upon request
CASA Letter of Validation
Available upon request
Data Processing Addendum
Available upon request
Security Questionnaires
SIG, CAIQ, or your organization's questionnaire
Available upon request
Contact the Account Team

Report a security vulnerability to security@privacyhawk.com.

Frequently Asked Questions

Can PrivacyHawk read our employees' email?

No. The scan uses message-metadata permissions, which exclude message bodies and attachments, and PrivacyHawk retrieves only the sender's domain and the date. Message content, subject lines, attachments, and individual sender addresses are never retrieved or stored.

Why does the consent screen list more than PrivacyHawk uses?

Google and Microsoft permissions come in fixed bundles. The narrowest permission that includes the sender also covers other header fields. This page shows what each permission allows next to what PrivacyHawk retrieves and stores.

Is PrivacyHawk Enterprise used to monitor employees?

No. It reports on the third-party companies holding the organization's data, not on employee behavior. The Terms of Service prohibit using its output in hiring, compensation, discipline, or other employment decisions.

Is our data used to train AI?

Google Workspace data is never used to train, fine-tune, or evaluate any AI or machine learning model, in any form. Microsoft 365 data is used for training only in fully anonymized form, and no personally identifiable information is ever used. Neither is used for advertising or provided to third parties for model training, and third-party AI processing happens under contracts that prohibit retention and training.

Where is our data stored, and when is it deleted?

In Google Cloud data centers in the United States, encrypted at rest and in transit. Upon revocation, a deletion request, or cancellation, tenant data, everything derived from it, and related logs are deleted immediately, and backups within 7 days.

Who is the data controller for tenant scans?

The customer organization is the data controller. PrivacyHawk acts as its processor under the Terms of Service.

Data Sharing

Subprocessors

PrivacyHawk shares data only with the providers required to operate the service, under contractual confidentiality, security, and data protection obligations.

ProviderPurposeData LocationApplies To
AirbyteData pipeline to data warehouseUnited StatesApp, Enterprise
AmplitudeProduct analyticsUnited StatesApp, Enterprise
AnchorBrowserCloud browser sessions for data broker removal requestsUnited StatesApp
AnthropicAI model inference (secondary)United StatesApp, Enterprise
Apple App Store, Google PlayIn-app purchases and billingPer providerApp
CloudflareCDN, DDoS protection, traffic filteringGlobal edgeApp, Enterprise
CyvatarManaged security monitoringUnited StatesApp, Enterprise
Google Cloud Platform (including Firebase and Vertex AI)Hosting, storage, processing, user authentication, and AI inference (Gemini)United StatesApp, Enterprise
IntelHawkBreach and dark web exposure dataUnited StatesApp
IntercomCustomer supportUnited StatesApp, Enterprise
IterableEmail and in-app messagingUnited StatesApp
MongoDB AtlasDatabase hostingUnited StatesApp, Enterprise
OpenAIAI model inference (secondary)United StatesApp, Enterprise
RevenueCatIn-app subscription managementUnited StatesApp
SentryError monitoringUnited StatesApp, Enterprise
SingularMobile app install attributionUnited StatesApp
StripeWeb payment processingUnited StatesApp

PrivacyHawk also sends opt-out and deletion requests, at your direction, to the companies that hold your data. This is part of the service.

For subprocessor change notifications, contact the PrivacyHawk account team.