Security and trust
What we can see, what we keep, and for how long
The whole model on one page: consent-based read-only access, an assessment that runs in your browser, a short list of what is stored, and the guarantees of the auditor link. Every statement here matches the product’s data-persistence inventory.
How access works
What runs in your browser
What is stored, and for how long
Assessment data is not stored server-side. The following records are.
| Record | Purpose | Retention |
|---|---|---|
| Company and user accounts | Sign-in and access control | Until deleted by the administrator |
| Tenant registration | Application id, directory id, package and entitlements | Until the tenant is deleted |
| Evidence you attach to a control | Text and screenshots you add for your audit | With the tenant record; deleted with it |
| Auditor snapshots | A read-only copy of one framework’s status and proof | 24 hours, then refused and pruned |
| Audit log | Sign-ins, administrative changes, link creation | 90 days |
| Demo requests | Your contact details from the form on this site | Not deleted automatically |
- Company and user accountsSign-in and access control
- Retention
- Until deleted by the administrator
- Tenant registrationApplication id, directory id, package and entitlements
- Retention
- Until the tenant is deleted
- Evidence you attach to a controlText and screenshots you add for your audit
- Retention
- With the tenant record; deleted with it
- Auditor snapshotsA read-only copy of one framework’s status and proof
- Retention
- 24 hours, then refused and pruned
- Audit logSign-ins, administrative changes, link creation
- Retention
- 90 days
- Demo requestsYour contact details from the form on this site
- Retention
- Not deleted automatically
Request a demo
Questions your security review will ask
Bring them to the demo. We can walk through the consent screen, the permission list and the stored-data inventory on a live tenant.