Privacy Policy

Your privacy is fundamental to our mission. This policy explains how we collect, use, and protect your data.

Last updated: December 3, 2025

Information We Collect

Account Information

When you sign in with Microsoft Entra ID, we collect your email address, display name, and organizational information necessary to provide our security dashboard services.

Device & Security Data

We collect device information, security alerts, compliance status, and incident data from your Microsoft 365, Intune, and Defender environments to calculate security scores and provide threat detection.

Usage Analytics

We collect anonymized usage data to improve our services, including feature usage patterns, dashboard interactions, and report generation metrics.

How We Use Your Data

Security Posture Analysis

Your data is used to calculate real-time security scores, detect threats, identify compliance gaps, and generate actionable recommendations for your organization.

AI-Powered Insights

We use AI to analyze security incidents and provide plain-language explanations, business impact assessments, and remediation recommendations. All AI processing follows strict data minimization principles.

Service Improvement

Aggregated, anonymized data helps us improve our detection algorithms, enhance user experience, and develop new security features.

Data Protection & Security

Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption. Sensitive credentials and tokens are additionally encrypted using envelope encryption.

Multi-Tenant Isolation

Your organization's data is logically isolated from other tenants. Each tenant has unique identifiers and access controls preventing cross-tenant data access.

Access Controls

We implement role-based access control (RBAC) with least-privilege principles. All administrative access is logged and audited.

Data Sharing & Third Parties

No Sale of Data

We do not sell, rent, or trade your personal or organizational data to third parties for marketing or advertising purposes.

Service Providers

We work with trusted service providers (cloud infrastructure, AI processing) who are contractually bound to protect your data and use it only as instructed.

Legal Requirements

We may disclose data when required by law, court order, or to protect our rights, safety, or the security of our users and the public.

Data Retention

Active Data

Security data and incidents are retained for 90 days by default, with configurable retention periods up to 2 years for compliance purposes.

Account Termination

Upon account termination, your data is securely deleted within 30 days, except where retention is required for legal or compliance reasons.

Backup Data

Backup data is retained for disaster recovery purposes and is automatically purged according to our retention schedule.

Your Rights

Access & Portability

You have the right to request a copy of your data in a structured, machine-readable format.

Correction & Deletion

You can request correction of inaccurate data or deletion of your data, subject to legal and contractual obligations.

Objection & Restriction

You can object to certain processing activities or request restriction of processing in specific circumstances.

Questions About Your Privacy?

Our data protection team is here to help. Reach out with any questions or requests.

Contact Us