Trust
Data protection
SurePosture is given privileged read access to Microsoft 365 tenants. This page explains exactly what it reads, what it keeps, how it is protected and how access is taken away.
Last updated 25 September 2026
Who is responsible for what
When you use SurePosture to assess a Microsoft 365 tenant, the data read from that tenant is processed on your instructions. You (or your client, where you are an MSP acting for them) are the controller, and [Company legal name] acts as your processor under a data processing agreement. Where you are an MSP, we are a sub-processor to you.
For the accounts of people who sign in to SurePosture, and for billing, [Company legal name] is the controller. That is covered by the privacy notice.
How SurePosture connects
SurePosture authenticates as its own multi-tenant Microsoft Entra application with application permissions, granted by an administrator of the tenant through Microsoft's admin consent screen. No password or credential of yours is given to SurePosture. If a client requires their own app registration instead, its secret is encrypted with AES-256-GCM, bound to that tenant's record, so it cannot be decrypted in the context of any other tenant.
Read permissions (assessment)
| Permission | Why it is needed | Required |
|---|---|---|
Organization.Read.All | Tenant profile, verified domains, technical contacts and assigned plans. | Yes |
Directory.Read.All | Users, groups, devices and directory objects that underpin most checks. | Yes |
User.Read.All | Account state, licence assignment and sign-in activity per user. | Yes |
Group.Read.All | Microsoft 365 groups, ownership, membership and guest exposure. | Yes |
GroupMember.Read.All | Resolves the membership of groups targeted by Conditional Access. | Yes |
Policy.Read.All | Conditional Access policies, authorization policy, security defaults, auth methods policy. | Yes |
RoleManagement.Read.Directory | Directory role assignments and PIM eligibility — the privileged access picture. | Yes |
Application.Read.All | App registrations, service principals, credential expiry and delegated consent grants. | Yes |
AuditLog.Read.All | Last sign-in timestamps (dormant account detection) and directory audit retention. | Yes |
Reports.Read.All | Authentication method registration and service usage reports. | Yes |
SecurityEvents.Read.All | Microsoft Secure Score, control profiles and security alerts. | Yes |
IdentityRiskyUser.Read.All | Identity Protection risky users and risk detections. | Optional |
DeviceManagementConfiguration.Read.All | Intune compliance and configuration policies. | Optional |
DeviceManagementManagedDevices.Read.All | Enrolled device inventory, compliance state and OS versions. | Optional |
MailboxSettings.Read | Inbox rules, to find mail being forwarded outside the organisation. Rule definitions only; no message content. | Optional |
SharePointTenantSettings.Read.All | Tenant-wide SharePoint and OneDrive sharing configuration. | Optional |
TeamSettings.Read.All | Teams guest access and meeting policy posture. | Optional |
Without an optional permission, the related checks are reported as not assessed and excluded from the score; they are never reported as passing. Email authentication checks (SPF, DKIM, DMARC, MTA-STS) need no permission: they read the public DNS records of your custom domains.
Write permissions (automation only)
These are only requested if you choose to use automated remediation, in a separate consent step. Even after they are granted, nothing can change in a tenant until automation is switched on for that specific tenant, a dry run has succeeded, and the change is approved by someone other than the person who proposed it.
| Permission | Used for |
|---|---|
Policy.ReadWrite.ConditionalAccess | Create or amend Conditional Access policies via an approved action. |
User.ReadWrite.All | Disable dormant accounts, revoke sessions, clear stale licences. |
Directory.ReadWrite.All | Remove redundant role assignments and stale directory objects. |
Application.ReadWrite.All | Revoke risky delegated consent grants and unused app credentials. |
What is read and kept
Each assessment keeps a trimmed snapshot of the data the checks need, and the results of those checks:
- People: user principal name, display name, account state, user type, licences assigned, last sign-in dates, MFA and authentication-method registration, department and job title where set.
- Configuration: Conditional Access and authorisation policies, directory role assignments, app registrations and consent grants, group settings and ownership, SharePoint sharing settings.
- Devices: device name, manufacturer, model, serial number, operating system and version, compliance and encryption state, enrolment and last sync dates.
- Security signals: Secure Score, alert counts by severity, risky users and risk levels.
- Email: public DNS records for your custom domains, and, with the optional permission, the name and external recipients of inbox rules that forward mail outside the organisation.
- Results: findings with their evidence, reports you generate, notes your team adds, and an audit log of actions taken in SurePosture.
Never read: email bodies or attachments, files and documents, Teams messages, calendar entries, passwords or authentication secrets. SurePosture does not request the permissions that would allow it to.
Where data is stored
The SurePosture service, its database and generated reports are hosted in the EU (Frankfurt) by Render. Data from Microsoft 365 is read from Microsoft's service endpoints for the tenant's cloud and written only to that database.
How it is protected
- Every workspace is isolated: records are fetched only through accessors that refuse rows belonging to another organisation.
- Connections to SurePosture use HTTPS. Session cookies are HTTP-only, secure and same-site.
- Passwords are stored as salted scrypt hashes. Session tokens, share links and invitation links are stored only as hashes.
- Stored tenant credentials are encrypted with AES-256-GCM.
- Logs redact secrets, passwords, tokens, cookies and keys before they are written.
- Report downloads are private and scoped to your workspace; share links expire and are not indexed.
- An append-only audit log records consents, assessments, report downloads and exports, finding updates, approvals and every change made to a tenant.
Signing in to SurePosture: with Microsoft, so your own Conditional Access and MFA apply, or with a password of at least 12 characters plus optional two-step verification from an authenticator app, which a workspace owner can make mandatory. Sign-in attempts are rate limited, and every sign-in, failed attempt and security change is recorded in the audit log.
Retention and deletion
- Assessment snapshots, findings and reports are kept while your workspace exists, so trends and change tracking work.
- Removing a tenant from SurePosture deletes its assessments, snapshots, findings and reports.
- To close your workspace and delete all of its data, contact [privacy contact email].
Revoking access
A tenant administrator can remove SurePosture's access at any time in the Entra admin centre: Identity → Applications → Enterprise applications → select the SurePosture application → Delete. Access stops immediately; the next assessment will fail and report that consent is missing.
Sub-processors
| Provider | Purpose | Data involved |
|---|---|---|
| Render | Application and database hosting | All data described on this page |
| [email delivery provider] | Sending notification and invitation emails | Recipient email addresses, tenant names and summary results |
| Stripe | Subscription billing | Billing contact and payment details (no tenant data) |
Incidents
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, with the information you need to meet your own obligations.
Contact
Data protection questions and data processing agreements: [privacy contact email]. Security issues: [security contact email]. [Company legal name] is registered with the Information Commissioner's Office under registration number [ICO registration number].