Skip to content
Tenant Excellence

Security and trust

What we can see, what we keep, and for how long

The whole model on one page: consent-based read-only access, an assessment that runs in your browser, a short list of what is stored, and the guarantees of the auditor link. Every statement here matches the product’s data-persistence inventory.

  • Read-only access

    Delegated permissions your administrator grants through Microsoft’s consent screen.

  • Runs in your browser

    The assessment reads your tenant from the browser session, not from our servers.

  • Tokens never stored

    Microsoft access tokens stay in the browser and are never stored on our servers.

  • You choose what is kept

    Only evidence you attach and 24-hour auditor snapshots leave the browser.

How access works

  1. 01Delegated, read-only permissionsYour administrator registers the application and approves the permissions on Microsoft’s consent screen. That screen is the authoritative list; nothing can be widened afterwards without a new consent.
  2. 02No write scopeThe assessment does not create, change or delete users, content, settings or resources in Microsoft 365 or Azure.
  3. 03Revocable by youConsent is visible in Entra ID under Enterprise applications and can be revoked there at any time. Deleting the tenant from the platform removes its evidence and auditor links.

What runs in your browser

  1. 01Reads happen client-sideThe browser calls Microsoft Graph, Azure Resource Manager, Resource Graph, Cost Management and DNS over HTTPS directly and evaluates every control locally.
  2. 02Tokens stay in the browserMicrosoft access tokens are held in the browser session and are never stored on our servers. The Azure relay forwards a bearer token per request and keeps nothing.
  3. 03Content is out of scopeThe service is not designed to read email, chat, file or recording content. It reads configuration and usage metadata.

What is stored, and for how long

Assessment data is not stored server-side. The following records are.

  • Company and user accounts
    Sign-in and access control
    Retention
    Until deleted by the administrator
  • Tenant registration
    Application id, directory id, package and entitlements
    Retention
    Until the tenant is deleted
  • Evidence you attach to a control
    Text and screenshots you add for your audit
    Retention
    With the tenant record; deleted with it
  • Auditor snapshots
    A read-only copy of one framework’s status and proof
    Retention
    24 hours, then refused and pruned
  • Audit log
    Sign-ins, administrative changes, link creation
    Retention
    90 days
  • Demo requests
    Your contact details from the form on this site
    Retention
    Not deleted automatically

Where AI data goes

AI insights are optional per tenant and call Microsoft’s Work IQ from your browser under your own Microsoft identity. The payload contains counts, statuses and control identifiers only — no names, addresses, domain names, resource names or evidence text — and does not pass through our servers. It requires the Work IQ service principal, consent and a Copilot-credits policy in your tenant.

The auditor link

  • Read-only: the auditor sees status, findings and tenant-sourced proof, nothing else
  • Scoped to one framework and one tenant
  • No account, no Microsoft sign-in on the auditor’s side
  • Expires 24 hours after creation and is refused afterwards
  • Every creation is written to the audit log with actor and time

Separation of duties

Platform administration and customer data are separate surfaces. A platform administrator can create a company, register its tenant and set its package, but cannot open its assessment, read its evidence or issue an auditor link. The server enforces this.

Request a demo

Questions your security review will ask

Bring them to the demo. We can walk through the consent screen, the permission list and the stored-data inventory on a live tenant.

0 / 2,000