Bailey Guard by CGA privacy policy

Bailey Guard by CGA is a no cost browser extension from Cyber Grants Alliance. It warns you, and blocks the page, when a website imitates the Microsoft 365 sign in page to steal your password. This policy covers the extension only. Our website has its own privacy policy.

What does Bailey Guard collect?

Nothing. Bailey Guard does not collect, store on our servers, sell or share any personal information. That includes:

  • Your passwords or anything you type
  • Your browsing history
  • The content of the pages you visit
  • Your name, email address or location

Bailey Guard has no ads, no tracking and no analytics.

Where does the checking happen?

Inside your browser. Bailey Guard looks at pages that show a Microsoft style sign in form and decides on your device whether the page is real. Your settings, a cached copy of the detection rules and simple counters (pages blocked, real sign in pages confirmed) are kept in your browser's local storage and never leave your device.

Does Bailey Guard connect to the internet?

On its own, it makes one kind of request: it downloads a public detection rules file from GitHub (CyberDrain Check), about once a day, so it keeps up with new scams. That request sends no information about you or the pages you visit. If the download fails, Bailey Guard uses the copy of the rules packaged with it.

What about the optional reporting settings?

Bailey Guard's settings include optional reporting to a CIPP server or a webhook, for IT teams that want to see blocked pages across their organization. These are off unless you, or the organization that manages your browser, turn them on. When they are on, details of a detection, such as the address of the blocked page, go only to the server that you or your organization entered. They are never sent to Cyber Grants Alliance.

Why does Bailey Guard ask for these permissions?

  • Access to all websites. A fake sign in page can be hosted on any website, so the check has to run on every page. Page content is analyzed in your browser and is not collected or sent.
  • Tabs and active tab. To check a page as soon as it opens, show the badge for each tab, and replace a blocked page with the warning.
  • Storage. To keep your settings, the detection rules and the counters in your browser.
  • Scripting. To protect tabs that were already open when Bailey Guard was installed.
  • Web requests. To read page response headers as one sign of a real Microsoft page. Headers are read in memory, never stored long term and never sent anywhere. Bailey Guard does not block or change your requests.
  • Alarms. To refresh the detection rules once a day.

Is the code public?

Yes. Bailey Guard by CGA is based on Check by CyberDrain and is licensed under the GNU Affero General Public License 3.0. Its source code is published at github.com/capitalcybercompliance/ares-da-bailey-guard, so anyone can check what it does.

Changes and questions

If this policy changes, we will update this page and its date. Questions about Bailey Guard or this policy: contact Cyber Grants Alliance.

Ready to Protect Your Business?

Join the businesses strengthening their cybersecurity with CGA.