This policy explains the cookies and similar technologies used by the LibraCyber application at app.mantra.ms, and by the sign-in service at auth.mantra.ms that you pass through when you log in. It tells you what each one does, how long it stays on your device, and how to change your choices.
The cookies used on our public website are different, and are described in our website cookie policy. How we collect and handle personal data inside the application is described in our application privacy policy.
A cookie is a small text file that a website asks your browser to store on your device. Cookies let a site recognise your browser between page loads — which is how you stay signed in after entering your password. Some technologies work the same way without being cookies, such as local storage and session storage; where we use those, we list them in this policy too.
We group cookies the same way the consent banner in the application does:
You choose which of the optional categories to allow the first time you sign in, and you can change your mind at any time from Cookie settings in the application menu.
These cookies are required to authenticate you and to keep your session secure. They are set by Auth0, the identity provider we use to run sign-in, and by the application itself. They cannot be turned off.
| Name | Provider | Purpose | Retention |
|---|---|---|---|
auth0 |
Auth0 — set on auth.mantra.ms |
Keeps you signed in. This cookie holds your single sign-on session, so you are not asked for your password again every time you open the application or move between our services. | 1 month |
auth0_compat |
Auth0 — set on auth.mantra.ms |
Serves exactly the same purpose as auth0. It exists as a fallback for older browsers that do not understand the SameSite=None cookie attribute. |
Same as auth0 |
did |
Auth0 — set on auth.mantra.ms |
Identifies your device so that our attack protection can spot suspicious sign-in activity, such as repeated failed password attempts or credential-stuffing attacks against your account. | 1 year |
did_compat |
Auth0 — set on auth.mantra.ms |
Serves the same purpose as did, as a fallback for browsers that do not support the SameSite=None cookie attribute. |
1 year |
auth0.is.authenticated |
LibraCyber — set on app.mantra.ms |
Records that a sign-in session exists, so that when you open the application it knows to restore your session silently instead of sending you back to the login screen. It contains no personal data — only a flag. | 1 day |
_legacy_auth0.is.authenticated |
LibraCyber — set on app.mantra.ms |
Serves the same purpose as auth0.is.authenticated, as a fallback for older browsers. |
1 day |
Depending on how your account is configured, Auth0 may set additional strictly necessary cookies during specific steps of the sign-in flow — for example, to remember a browser you have approved for multi-factor authentication, so that you are not challenged on every sign-in.
These are set only if you accept analytics cookies. We use PostHog to measure how the application is used — which pages are opened, which features are used, and where the interface produces errors — so that we can prioritise improvements. Your analytics data is processed in the European Union.
| Name | Provider | Purpose | Retention |
|---|---|---|---|
ph_phc_gpml4RN2puVa2JTGWV2vEUxks1flm7t9TrNQaXn9MfF_posthog |
PostHog, EU region (eu.i.posthog.com) |
Stores an anonymous identifier for your browser, along with basic session information, so that a sequence of actions can be recognised as one visit rather than a series of unrelated events. | 1 year |
We configure PostHog restrictively. Text and element attributes on the page are masked before an event is sent, so the contents of your dashboards, email subjects and user lists are never transmitted. IP address, geolocation and advertising identifiers are stripped from every event. We do not use these cookies for advertising, and we do not share analytics data with advertising networks.
If you decline analytics cookies, or withdraw your consent later, PostHog is not loaded at all and any analytics cookies already on your device are deleted.
These are set only if you accept communication cookies, and only for administrator accounts that have the product-updates widget enabled. We use Beamer to show release notes and product announcements inside the application.
| Name | Provider | Purpose | Retention |
|---|---|---|---|
_BEAMER_USER_ID_* |
Beamer | Identifies your browser to the announcements widget, so that the same announcement is not shown to you repeatedly. | |
_BEAMER_FIRST_VISIT_* |
Beamer | Records the first time you opened the announcements widget, which is used to decide which announcements are new to you. | |
_BEAMER_LAST_UPDATE_*, _BEAMER_DATE_*, _BEAMER_LAST_POST_SHOWN_*, _BEAMER_BOOSTED_ANNOUNCEMENT_DATE_* |
Beamer | Track which announcements you have already seen and when, so the notification badge and highlighted announcements stay accurate. |
If you decline communication cookies, or withdraw your consent later, the widget is removed from the interface and these cookies are deleted from your device.
The following items are not cookies, but they store data in your browser and are covered by the same rules, so we list them here.
| Name | Type | Purpose | Retention |
|---|---|---|---|
cookie-consent |
Local storage | Records the cookie choices you made and the version of the banner you responded to, so that we honour your decision and do not ask you again on every visit. | Until you clear your browser storage, or a new version of the banner is published |
user-preferences |
Local storage | Remembers interface preferences, such as the filters and display options you last used, so the application looks the way you left it. | Until you clear your browser storage |
ph_..._posthog |
Local storage | PostHog stores a copy of the analytics identifier described above in local storage as well as in a cookie. Only set if you accept analytics cookies. | 1 year |
| Managed-service-provider session token | Session storage | When a partner administrator opens your environment through a delegated session, this holds the access token for that session. | Deleted when you close the browser tab |
You can review or change your consent at any time by opening Cookie settings in the application menu. Your new choice takes effect immediately: services you have declined stop loading, and the cookies they had already set are deleted.
You can also manage cookies in your browser settings, where you can delete existing cookies or block new ones. Bear in mind that blocking or deleting the strictly necessary cookies listed above will sign you out of the application and prevent you from signing back in.
We update this policy when the cookies used by the application change — for example, when we add or remove a third-party service. The date at the top of the page tells you when it was last revised. If a change affects the optional categories, we will ask you for your consent choices again.