The Microsoft 365 Copilot app is your AI-first productivity app for work. Chat with your AI assistant, create content, manage projects and quickly find files on the go.
Quick Verdict
Best for: Microsoft 365 users managing work docs on mobile
What It Means For You
Usage and diagnostic data is collected via Microsoft 1DS and AppCenter telemetry, and install attribution is tracked through Klondike and Google Install Referrer. Authentication tokens are stored with strong device-level protection, and Firebase analytics is disabled. Microsoft Intune MAM support is available for organizations requiring managed device policies.
Quick Verdict
Best for: Microsoft 365 users managing work docs on mobile
What It Means For You
Usage and diagnostic data is collected via Microsoft 1DS and AppCenter telemetry, and install attribution is tracked through Klondike and Google Install Referrer. Authentication tokens are stored with strong device-level protection, and Firebase analytics is disabled. Microsoft Intune MAM support is available for organizations requiring managed device policies.
Method and Limitations
Static analysis only. CITT reviewed the code of this build without running the app, so runtime behavior was not observed. The findings below describe the analyzed build and may not reflect server-side controls or later versions. CITT makes no determination about compliance with any law or platform policy; it reports what the artifacts contain and cites the published guidance so a reader can compare.
Data Security
1 totalNetwork Security
2 totalPrivacy
2 totalVersion diff is on the Developer plan. See developer plans.
Context Tags
Package
com.microsoft.office.officehubrow
Version
16.0.19929.20060 (build 45158845)
Analysis Date
Apr 17, 2026
Classes Analyzed
15,000
Feedback helps us improve our analysis
Enterprise users on managed Intune devices can use safely. Privacy-conscious users should be aware of telemetry collection and an authentication bridge security issue before installing. IT administrators should review whether advertising identifier collection aligns with organisational privacy policies.
Data Security - 1 finding (1 medium)
Network Security - 2 findings (1 medium, 1 low)
Code Safety - 0 findings
Privacy - 2 findings (1 medium, 1 low)
The following third parties may receive your data:
Security: 92/100
Privacy: 91/100
The app's privacy practices could be strengthened by:
Consent Gating for Telemetry
Telemetry collection, including voice session data classified as personal information, begins at app startup before any consent acknowledgement can be confirmed. Adding an explicit consent check before the first telemetry transmission would align with GDPR requirements for processing personal data.
Advertising Identifier Use in Enterprise Context
The advertising identifier is collected for install attribution without an in-app mechanism to opt out independently of the system-wide ad tracking toggle. For an enterprise productivity app, organisations and privacy-conscious users should have a direct way to disable this collection.
Full Coverage of Local AI Session Storage
Some Copilot session metadata stored locally - including document sensitivity labels and source document references - is not handled per security standards. Extending the same protection already applied to the main response content would reduce exposure on shared or compromised devices.
Restrict Authentication Bridge Origins
The in-app authentication bridge that handles Microsoft 365 sign-in flows within embedded pages accepts messages from any page origin. Restricting this to known Microsoft domains would prevent a compromised or malicious embedded page from triggering authentication flows.
Scope Cleartext HTTP Permissions
The current configuration allows unencrypted HTTP connections to any host. Restricting this allowance to only the specific legacy on-premises server scenarios that require it would prevent accidental unencrypted data transmission in other contexts.
App Type: Enterprise AI productivity app (high sensitivity - handles work documents, emails, and voice input)
Classes Analyzed: 15,000
Third-Party Services: 24
Context Tags: enterprise, productivity, office, ai, documents, voice, cloud, ads
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
Developer: Microsoft Corporation
Version: 16.0.19929.20060 (build 45158845)
Analysis Date: 2026-04-17
Package: com.microsoft.office.officehubrow
Developer not yet contacted