Privacy Policy
This Privacy Policy explains how TenantVigil collects, uses, safeguards, and retains information related to our website, customer accounts, and Microsoft 365 security posture service.
What we collect
When you sign in or connect a tenant, we may collect account and identity information such as your name, email address, organisation name, Microsoft Entra identifiers, and tenant metadata needed to authenticate you and scope the correct workspace.
To operate the product, we also store tenant configuration evidence, assessment results, control history, remediation context, audit events, billing-related account metadata, and customer-generated workflow inputs such as notes, risk acceptances, and report preferences.
- Account and identity data used for authentication, support, and tenant administration.
- Tenant and configuration evidence retrieved from Microsoft 365 to assess posture.
- Usage, audit, and operational telemetry used to secure and improve the service.
How we use information
We use personal and tenant data to authenticate users, run assessments, generate posture and compliance outputs, provide reporting, support drift monitoring, and maintain the reliability and security of the service.
We may also use limited service and product analytics to understand adoption, improve workflows, troubleshoot incidents, and plan new functionality. We do not sell personal information.
How TenantVigil handles Microsoft 365 data
TenantVigil is designed around read-only assessment access by default. The product evaluates Microsoft 365 settings and evidence but does not automatically remediate your tenant or change your production configuration as part of a standard assessment flow.
Customers remain responsible for deciding whether and how to act on findings, guided remediation steps, and risk-acceptance decisions generated inside the service.
Security and storage
We use technical and organisational controls intended to protect customer data, including encrypted transport, encrypted storage for sensitive data, access controls, logging, and tenant isolation controls in our application and data layers.
Because no service can guarantee absolute security, customers should also maintain good administrative hygiene in their own Microsoft 365 environment, including least privilege, MFA, and review of connected applications.
Sharing and subprocessors
We may share data with service providers that help us host, secure, support, and operate TenantVigil. We may also disclose data where required by law, to protect rights and security, or in connection with a corporate transaction.
We may produce aggregated or de-identified service analytics that do not reasonably identify a specific customer, user, or tenant.
Retention and deletion
We retain customer data for as long as needed to deliver the service, maintain security and auditability, comply with legal obligations, resolve disputes, and enforce agreements. Retention can vary by data type, contract, and operational need.
If you need export or deletion support, contact us and we will handle the request in line with your agreement, our operational obligations, and applicable law.
Your choices and contact details
Depending on applicable law, you may have rights to access, correct, delete, or restrict certain personal data. Where TenantVigil acts as a processor for customer data, the relevant customer remains responsible for handling the underlying data subject request.
For privacy inquiries, DPA questions, or data rights requests, email privacy@tenantvigil.com.