IT and privacy
For IT administrators
The sender and domains to allow, browser requirements, putting the app on devices, and notifications.
This guide is for your organisation's IT administrator, getting ready to roll out Cyberact. Cyberact is a web app: nothing is installed on your servers or workstations, and it needs no integration with your systems. People sign in with their own work email and a one-time code; there are no passwords.
The sender to allow
Every message from Cyberact comes from support@cyberact.io, with the sender name Cyberact. Add it to your allowed senders so that sign-in codes and invitations don't end up in spam or quarantine.
| Message | Subject |
|---|---|
| Sign-in code | Your Cyberact sign-in code (in Finnish, Cyberact-kirjautumiskoodisi) |
| Invitation | You have been invited to Cyberact (in Finnish, Sinut on kutsuttu Cyberactiin) |
| A manager's reminder to inactive people | Tietoturvakoulutuksesi odottaa · Your security training is waiting |
- The messages are plain text, with no attachments.
- The sign-in code is only in the body of the message, never the subject, so it doesn't show on a locked phone's notification.
- The messages are sent through Cyberact's mail service (Hostinger) from the cyberact.io domain.
A code is valid for 10 minutes. If a message sits in quarantine for longer, the code will have expired. See also The sign-in code doesn't arrive.
Invitation links and link scanning
The link in an invitation looks like https://app.cyberact.io/_gate/invite/… A link scanner that opens the link before the person does won't use the invitation up. The link only opens a welcome page; the invitation is accepted when the person signs in with a code.
The domains to allow
| Address | What for |
|---|---|
| app.cyberact.io | The app, signing in, the manager console and user management |
| cyberact.io | The website, pricing and the privacy notice |
| docs.cyberact.io | These guides |
| cart.cyberact.io | Ordering |
The app loads everything from its own address. It uses no third-party scripts, fonts, analytics or advertising. All traffic is encrypted (HTTPS). The server and the data are in Hostinger's data centre in Germany (EU).
The app can't be embedded in a frame (iframe) on another site, such as your intranet or a learning platform. Link to https://app.cyberact.io/ instead.
Sign-in limits
- Up to five codes an hour, and ten a day, can be asked for one email address.
- The limit for one public IP address counts only wasted requests: codes asked for addresses that have no access, and codes typed wrong. Codes for your own people don't use it up, so a whole office behind one IP address can sign in for the first time at once.
- A network that someone in your organisation has signed in from in the last 30 days gets a higher limit. We keep only a hashed form of the IP address, not the address itself.
- A code stops working after the fifth wrong attempt.
If many codes are asked from your network for addresses that aren't in Cyberact, no codes are sent to anyone from that network for an hour, your own people included. If someone is told a code is on its way but none arrives, they can wait an hour and try again, or contact support@cyberact.io.
A session ends when the app hasn't been used for a week, and at the latest 30 days after signing in. People then sign in again with a code.
Browsers
Cyberact runs in the browser on computers, tablets and phones. The app is built for modern browsers: Chrome 87, Edge 88, Firefox 78 and Safari 14 or later. We recommend keeping browsers up to date.
The browser needs to allow:
- JavaScript
- cookies for app.cyberact.io. The session cookie keeps people signed in; it isn't used for tracking.
- local storage and service workers. These let the app keep working through a short loss of connection and show notifications.
Progress is saved on the server whenever the device is online, so it isn't lost when someone switches device or their browser data is cleared.
The app on devices
Cyberact isn't in the app stores. It is a web app that people can add to their phone's home screen, or install from a desktop browser so it opens in a window of its own.
- iPhone and iPad: open app.cyberact.io in Safari, tap Share and then Add to Home Screen.
- Android: open app.cyberact.io in Chrome and choose to install the app, or add it to the home screen, from the browser menu.
- Computers: in Chrome and Edge, you can install the app from the address bar or the browser menu.
If you push shortcuts to devices through device management, use https://app.cyberact.io/.
Notifications
A learner can turn on the Daily quiz reminder in their profile. It is a browser notification that reminds them if the daily quiz is still waiting.
- It is off by default and is turned on one device at a time. The default time is 18.00 in the person's own time zone.
- The notification holds only a short title and text. It has no name, email address or figures.
- On iPhone and iPad, notifications work only when Cyberact has been added to the Home Screen, and they need iOS or iPadOS 16.4 or later.
- Notifications travel through the browser maker's push service (Google, Mozilla, Apple or Microsoft). If your organisation blocks those services or browser notifications, the reminders won't arrive. Everything else in the app works as normal.
A manager's reminders to inactive people are emails, and they come from support@cyberact.io.
Privacy and security
What data Cyberact handles, where and for how long, is in Privacy and your data. How the data is protected, what is agreed about its processing and how to report a vulnerability is in Security and data handling.